Skip to main content
Right of Boom
January 30, 2025

The Cybercall: Positioning & Selling Your Security Stack

In this video, Wes Spencer, Phyllis Lee, Ben Harrell, and Ryan Eichler discuss strategies for MSPs to integrate cybersecurity into their offerings and how to effectively sell these services. They explore the importance of using security frameworks like CIS, the role of cyber insurance in driving security adoption, and the challenges of transitioning to an MSSP model. Additionally, they share insights on sales strategies, including hiring practices and compensation plans, to help MSPs grow in the competitive cybersecurity landscape.<ul><li>The importance of using a security framework like CIS in MSP sales processes to demonstrate existing security measures and identify additional needs.</li><li>The evolution of cybersecurity as a continuous process rather than a finite project, emphasizing that security measures need to be adaptive and ongoing.</li><li>The potential and strategies for Managed Service Providers (MSPs) to move upmarket and serve larger clients by offering comprehensive security solutions and partnering with established security providers.</li></ul>

Guests

Andrew Morgan

Video Transcript

We're live, baby. Okay, now we're live. Okay. We were talking about Cheetos in the Green room, and now I'm hungry. Well, Phyllis brought enough for everybody. Hey, by the way, if you're, if you're, if you're, uh, tuning in today, Phyllis will personally send you some Cheetos. Just, you know, get exactly. I'll, I'll se I'll, I'll, I'll send you her, uh, email. She won't have too many there. I'm trying To get them to sponsor me. That's awesome. Boas. All right. Um, so, hey, everybody. Welcome.

Um, I, I'm as, Hey, did anyone go to IT Nation, by the way? They did a heck of a job. I think that was really cool. Um, looks like few people on the call here. And, um, just real quick, if you guys go all the way up to the beginning of chat, I just put a few things in there. I just wanna make, make announcements easy today. Um, first, um, the person that ran the Pre-Day event at I at Write a boom last year, Wes, who's, how awesome is Bob Bullock.

Um, he is, uh, black Hills top pen tester for the cloud. Um, he's gonna be doing a, um, securing Office 365 and Azure tomorrow. The URLs there highly encourage you to see that. Um, cyber Cast Control 14 is out. This is one of the best, I think, like ever. I always think it's better than the next one, but it was so good. Phyllis decided to change the name of the control, uh, based on the discussion that Ryan had with Wes. And, and so it's pretty, pretty, it was pretty impactful.

Uh, it was such a good secure, Ryan had five minutes of, of security that I, I needed a cigarette at the end. It was so good. Um, and then it Was like Ryan was, you know, you give him all this, this, this leave and he's just itching to get back in it, maybe. And that's what he did. He dropped some bombs. It was good. Yeah, he was phenomenal in it. Um, so just fantastic, you know, content and enablement for all Ms. P and SSPs out there.

Okay, um, just real quick, um, you're gonna start hearing more about the pre-Day events at right of Boom, the original pre-Day, which Strand and Hammond is sold out. Now you're gonna start hearing about the Diamond Platinum sponsors. The first one I'm gonna tell you about is the Huntress Pre-Day. Wes, this is a really cool one with you, Eric TILs and Chris Lahr. Um, this is gonna be not your typical tabletop.

Um, this is gonna be literally a high pressure situation where you're gonna have, um, crisis management and legal involved with Eric Tilts. Um, and, and he's gonna be signaling back and forth. There'll be only a limited amount of room there. Um, it's available to people that are registered. If you're registered, you can email me. I put my email in there. And last but not least, our friend Jason Slagel, and you're, I see Wes wearing one of his CNWR shirts.

He and a bunch of guys, which were pretty amazing, uh, had their beard saved, by the way, at it, nation raised two over $200,000, uh, which was pretty amazing. Um, but this is a really cool one on the role, uh, you know, the risk management MSP's gonna have to be aware about for filling out cyber questionnaires. All right, I think I got 'em all out. Whew. Let's get into it. Um, so I wanted to bring back Ryan. Um, Gary couldn't make it today, but we have Adam, who I'll introduce momentarily.

A lot of you guys know him. Um, I wanted to bring back Ryan Keller and actually Ryan's counterpart that helped build Interra this, their former CSO Ben Harrell, who also introduced momentarily. If you think about it, we're in the final stages of 2022 here, Wes. And we have really got to, you know, again, when, you know, whenever I was in sales, and, you know, back to aging myself, but certainly if you're an MSP, you really want to be gearing up now for 2023. What does your pipeline look like?

What are your metrics look like? Um, and, and Adam, I can see him shaking, 'cause I know he does it day in and day out as a, you know, CRO and owner led organization. So, um, security services is something that Ben and, and, and, and, and Ryan are very passionate. So I wanted to bring them back. So, without further ado, um, here's what I wanted to do. Let's get into some introductions. So I'm gonna start off Ryan. Thanks. Welcome back. Uh, a little bit about yourself.

We'll go to Ben and then Adam. Yeah. Uh, Ryan ecl been in the, uh, MSP space for about eight years. Uh, absolutely love it. Passionate about it. I think, uh, as break fix was to MSP, uh, security is the, the kind of new conversion that everyone's trying to figure out. So, uh, just excited to, uh, jump in and have some conversations and, and help people think differently from a go to market perspective and, and getting growing. So, thanks for having me. Yeah, It was very cool.

You said that, Wes, what do, Wes, do you remember how you turned where we were? Uh, yeah, about being break fix of Emma? Ryan, you just, I was gonna slip that question. Andrew, you gotta quit reading my mind, brother. I feel like we're in this break fix era of security right now, right? Mm-Hmm. We went from it, like break, fix it into managed it. And then now we're in the same era with security that many times you're like, here's the list. What would you like? I think you need this.

Maybe I have three or four options, and, and I, I'm kind of wishy-washy about it, and we feel like we're still in break fix security at this point. Yeah. Yeah, I agree completely. Yeah. We gotta get out of that too. Cool. Ben, welcome. Uh, awesome to have you. Not often do you find CISOs that are sales minded and excited to be on sales call, so I really appreciate you. Tell us a little about yourself and what you're doing these days. My name is Ben Harrell. I work with Friday Illumio.

I'm the head of incident response and managed services before that. Ryan and I both, uh, were in an MSP together, that we went through the M-S-B-M-S-S-P journey, which was fun. And before that, I was a CIO CSO role for a, uh, large law firm in the Midwest. Happy to be here. Hey, great to have you. So, Adam, I wanted you to fill in for Gary specifically because you help a ton of MSPs and you do it, uh, out of the goodness of your heart. You don't ever ask for any money.

Um, but you've been in the, uh, uh, uh, chief Revenue Officer role for many years. Tell us a little about yourself and what you're doing these days. Yeah. Hey, Adam Slatkin, for those of you that don't know me, uh, started off actually with Andrew when we were both at Kase, uh, in the early days crossover to ConnectWise in the early days when nobody could spell MSP. Imagine that back then.

And then, um, after the exit of ConnectWise, went and built a company called Line Guard, those that you all may be a partner there, I'm still involved there. And then, uh, launched Cyber Fox with the co-founder of ConnectWise. Uh, David Bellini. I love sales. I live in it. I mean, uh, my calculations for next year are all over my boards. Anybody that ever wants to, uh, talk, go to market. I help hire fire, build comp plans, anything that I can do to help MSPs and give back.

Uh, I've been doing it for about seven years. Love, love getting in it with you guys. All you gotta do is hit me up on LinkedIn and always glad to help out. That's awesome, Adam. And, And he means that too, guys. I've seen, I've seen Adam take people up on that. Oh, yeah. I, I absolutely spends tons of time Yep. Uh, with them. And there's, there's no invoice that comes behind it. So thanks for all you, you do, Adam. Um, okay. So, Wes, you are up first today. Yeah. Uh, let me let you take over.

All right, sounds good. So, Ben, why don't we start with a bit of a role play. We're just gonna jump into this earlier. All right? So I want you to assume Sure. That I am a, uh, client of yours. I've been with you for three or four years. We're friends. I've got a trust relationship with you, right? So I know you, you know me. Um, I've been relatively happy with your services, but I'm a bit persnickety and I'm super cheap, right?

So you've come to me and we're talking, and, and, and so here's my response. I'd love to kind of hear you role play this back to me and kind of chat about how you would handle this. Okay. So, so Ben, like, here's the thing, man. Like, I don't know, man. I feel like I've been doing this security stuff for a while. You've been doing it. You put in all this stuff for years. I've never been hit by anything. Why should I pay more?

Like, you're coming to me and you're saying, I gotta pay X amount more here, and I'm just, I, I'm really struggling with why I need to do that, right? Because nothing in my past has ever happened that caused me to think about it. I'm just not really open to making these kind of changes. Why do I gotta pay more?

So though, I would say to you as a client is, you know, uh, traditionally in MSP space, we followed security best practice from an IT framework perspective, really we follow to the best of our abilities. What's follow with things changing in the environment with what we're seeing in the news, we've decided to adopt, usually we'll say something along the lines like an open source control security framework.

We have found we're actually probably doing 50 to 60% of what's within that framework by the virtue of our service delivery, be it our existing patch management, our, uh, our single sign-on our multi-factor authentication. But with the adoption of that framework, we adopt it to ourselves to protect ourselves and all of our clients. We decided to bring additional controls into the client space. And that's usually the type of conversation we'll have with a client.

Most of 'em really understand with the heightened security that's going on. And like cyber is really top of mind for everybody. Even the smallest clients, there are like four person shops. Could be a car wash, could be an ice cream store. These, all these concerns exist. They out or hear about friends who've dealt with it or they have. So that was kind of like a very short snip of the approach. Usually we kind of started out the gate.

We usually supplement that with a roadmap or something that shows where we are, where we wanna be and such. Okay. So, um, I, that's good. And, and I think, and I know it's so hard to like, you know, take a whole relationship and summarize in and sum up Yeah. But appeal a couple things outta that. The thought that were really good there is you, you're, you're big on making sure the client knows through these conversations that this is a, a journey and that things are changing, right?

That, that it's not, the security is not an absolute, security is not a finite thing. Security is not a project that we begin an end. So to peel outta that, can you elaborate a little bit more? You're, you're big on communicating that, that cybersecurity is an evolving process, right? And they have to keep up. Is that sort of what you're saying? Uh, correct. So, uh, whenever you follow a framework and really kind of what we talk to clients, those things update, things change.

Nothing stays, we'll say consistent. The other thing we hit on is not all cybersecurity is tools. It's not like we're just shoving product on you. We are following different set of standards here, the standards we're following, you know, we're readapting your Azure environment, your Office 365 based on best practices. And so that are, you know, more focused maybe from pen testers and red teams and so on.

So, as we expose into it, what I will say at our, at Interra, which was very helpful to our approach from a security perspective, is we were doing incident response in engagements. We were doing a lot of them. And that really exposed a lot of people within the MSP. So it's, it's a combination of the buying of the clients and also your own internal employees need to be bought into the concept.

The way you approach cybersecurity is just, it's a little bit different, what we're used to doing from a managed service provider in a command center. I think so too, Wes, just to jump in a little bit, the conversation started with what we, the MSP ourselves were doing differently, right? So that was us adapting framework and controls us putting in tools and changes within our own environment as like a leader.

And then when we started talking to our customers, we would demonstrate what we've done ourselves. And then as a result of that, here's what we're expecting from our clients. And, and I would just echo everything Ben said. Um, you know, cyber is changing fast. MSPs have traditionally sat on the IT operations side of the house, and then we started sprinkling in next gen AV single sign on.

And it's, it's kind of communicating that same structure over the years that we've put around IT operations to drive down tickets. We needed to put that same sort of structure in place to, you know, to take care of the security risk that you have. I, I like that. Ryan. Oh, go ahead. Yeah, go ahead Andrew. Yeah, I was just gonna ask you real quick, Wes. I'm sorry, Ryan.

Ben, do you like using, I know we're talking hard terms here 'cause we're on a bunch of geeky people on call with us, but we're saying controls. Did you nuance safeguards in as a, you know, 'cause I think there's, even though it's nuanced, I think it means a, it, it, it, people can understand something like a safeguard versus necessarily a control. Did, did you guys nuance that a little bit? Uh, I'll answer that.

Our end, we did nuance only because when we did the presentation, we, part of the, we'll call it upgrade process, was going through, showing them where they currently are in a measurable way that they can see easily and show it to 'em. Now, what I'll say is people hear the word controls. It usually has the wrong connotation. A lot of people hear controls. They're thinking NIST 800 documents, super long documents written by professor. Most people can't use that.

We adopted, I'm gonna say CIS very easy to understand framework. We found that stakeholders, you know, who weren't technical understood it because A, it's written in like one paragraph, very easy to understand. You need to be an expert in cyber to understand what was being delivered. So I, we then use safeguards a great idea. Um, but we usually kind of supplemented it. Um, Brian, I, yeah, I would, I would agree with you s yeah.

And, and I think what you're getting at there, Ben, is like, how do I translate this into the language that makes sense and is receptive to my clients? Right? And, and sometimes I think we can be so sturt in our, our, our reliance on these like terms and these confusing things. It's like, if I'm gonna talk to a doctor, a good doctor's gonna be able to translate all this like medical jargon that I don't understand into what it means for me, right? And I think that we have to do that in security.

And sometimes we feel like, I think either a, because we ourselves are just not totally sure about, um, we're, we're just, we lack confidence ourselves. We knee-jerk into terms they don't know, or two, we think we have to do that to convince them. But the reality is both of those outcomes confuse the client because they just don't know what you're talking about. They hired you to be the expert.

And then when you come over their head with terms that they don't know, or this distinct distinction between those two safeguards and controls, they get lost. Don't you think that's the case? Yeah. You want to cater the conversation to the sophistication of the clients. Your smaller clients.

Obviously you want to, you know, dumb, maybe, I won't say dumb it down, but lower maybe the, the barrier of understanding you have clients and co-managed SNAs or do have, or larger environments that do have a vcso or a CIO in there that you're supporting there. It's when you can really get nitty gritty, I guess you could say, into those items. And they're probably aware of ci IS and other controls and space as is. Yeah. And So briefly, a hundred percent on That. Such a great point.

And, and this is where like, like for example, you talked to, if we had ZB on the call from Caltech, because they do so much work with banks, he can insert himself right into a bank conversation and actually use terms they know that make sense to them. Like, Hey, let's talk about how your management came out. Your, your management evaluations came out from your camel ratings, uh, from, from your last bank examination, CIO or CISO to banks and be like, he speaks my language, right?

Uh, let's talk about your cybersecurity assessment tool and let's see where you're at on that journey. He speaks my language. So I love that idea of like, it's not about just being simplistic. Sometimes you want to be super technical, but I think it leads to good. You have to have good discovery and know the audience that you're talking to, to know that angle, to take in a way that resonates with them, don't you think? Yeah, I agree with you completely.

And what I'll also say is, you know, a lot of MSPs are serve very specific verticals that they know better than anybody else. Their MSPs specialize in financial MSPs who specialize in healthcare. They know the client, they already know who they're serving to. So they probably already know how to cater that conversation. Okay, Ben. So, So yeah, if I could, Oh, Please, Ryan, go Ahead. Sorry, I just wanted to jump in with a point here too.

And I, and I don't wanna say we went on an apology tour, but when I was sitting in the, the CEO seat, um, before we started thinking in terms of framework to get cyber into our client stack, our method was whatever got us excited is what we sold. And, and that's how we positioned security. I'd go to a conference, someone would give away something cool, I'd come back and say, Hey, this is what we're doing.

We, we did start to acknowledge that their customers, listen, you know, I, we will take ownership of how we've operated in the past, which was onesie, twosie recommendations based on what has got, what got us excited. Where, when we pivoted into, you know, framework as a foundation, we would communicate to the, you know, our foundation is now based in framework. We're finding products and configurations that map back to those controls, right?

And that's how we started to get them thinking differently. So that I wanted to get them out of the mindset that every time they spoke with us, we were gonna try to sell them something versus them feeling like we had them on a journey, moving towards a target that they could see the end state.

So I just wanna like re-highlight that when you're, you know, when you make the switch with those initial conversations, you know, be transparent on what you've done in the past and how you're gonna operate differently. And that's very similar. I know some of us on the phone call have done break fix to MSP conversions. Like it's the same thing. Hey, when we do it this way, it's proactive. You know, it's, it's that same kind of sense.

So I wanna make sure that people, you know, when you, when you go and make the effort to do the transition, to move everyone over, you know, parallel the differences between how you're operating moving forward and, and what you've done in the past. I, I love that. And I think you nailed it there, Ryan. I mean, I think we can all raise our hand and say, we've been guilty about what I just quoted you in, in chat, right? Whatever got us excited is what we, what we tried to sell.

And then it, it, things fizzle out, right? We come back from IT nation, so many great conversations, and I'm gonna do this. And then the clients are like, what are you talking about? I don't even know what this language is. It's really, really well said. So, so Ben, let's flip the script then in, in, in light of what Ryan just said, if I'm talking to a client and they simply won't budge, they will not do it. What comes next?

I know you hear a lot of MSPs say, well, they're gonna have to sign a waiver to get out. I'm just gonna dump the client. Um, are those the two outcomes? Do you think there's more to it? What are your thoughts and approach here? Uh, it depends on the sophistication of the client. Uh, I thought You were gonna say the RR ben. Yeah. Uh, you know, that's, that's what was gonna say.

Um, you know, one thing is Ryan likes to say, and I agree, and forever, you know, if you're doing this, you're, you're blanket requiring everybody to follow all these products and everything you're doing for every three clients that you do have to raise, you know, your rate, you can afford to lose one, so to speak. Here's the reality. If one of your clients get breached, even if they signed a waiver, it will not look good on the MSP serving them, regardless if the waiver was signed.

You're not gonna go to all your clients and be like, yeah, we told 'em they should do it, but they signed a waiver. So, you know, it's not really our fault. Um, we need to align with the fact that from a reputational perspective, from a delivery perspective, clients who get breached reflect, even if it has nothing to do with the MSP, reflects negatively on the MSP. So are you saying is the only way to lose 'em? No, most clients, it's a conversation.

I think, uh, if we think back, uh, in MSP, we worked with, we out of maybe a hundred clients, we, or, or more, we had maybe one that didn't really wanna do it, and we said to ourselves, you know, we can afford to lose that one client. I don't want a data breach happening there. I don't want to do something.

Uh, if you put it like this, if you have clients who aren't to this day willing to do something like MFA, which is the most basic thing you could ever do, especially if Office 365, those are not necessarily clients. You, you want to have, I know it's hard because they're bringing in cash, but the damage it can be caused from them, it could be significant to your business. Yeah. Hey, can I add one thing there? You know, it's interesting.

I remember this conversation with Gary on a, a few cyber calls back, and the discussion was, don't be afraid to raise prices. And that maybe you can jump in there a little bit about your experience on that. But, you know, from working with the MSPs, I was, uh, to directly around pricing and packaging a lot, I was blown away how they were just taking on all this cost and not raising prices, having the confidence.

I will tell you, of all the years that helped MSPs raise prices outta all of 'em, we lost one customer and it was one that needed to be dumped. Um, what's your, what's your thoughts on that, Ben, on, you know, on that about raising prices? You know, maybe then talk a little bit, do you bake them into all you can eat? Is it a different price model? For sure. And, and can I put that in there? May maybe. Yeah.

Just one thing to that it should be, you know, did you guys take it as the reason, right, the, that is the reason you're gonna do business with us too, especially for a new client. What, what are your thoughts on that, whether it's Ben or, or Ryan? I would say it's both me and Ryan iLet actually. Uh, you know what, me and Ryan used to always say, we're very transparent.

He could say more about, about, uh, the pricing with existing clients, the challenges, existing clients, not the clients, right? Right, right, right. So if the existing clients, we, we were very transparent. We said, look, we're doing this outta abundance of caution. This is our margin. This is exactly how much money we're making on this. This is why for the service delivery side.

So we were very transparent with the pro, the extra cost that we were incurring as an MSP to deliver these services. So it wasn't like, Hey, here's an extra, you know, $50 per seat. Go figure it out. Like, Hey, we, we roll, uh, can I let 'em see behind the scenes? Like, this is what we're paying to add, you know, CrowdStrike, EDR, this is what we're paying to deploy privilege access management. This is, is what we're playing to, to put Avan on in place and so on. Here's why we're doing it.

Lock in now. You'll get it at this price. We're gonna give it to you as cheap as possible where we can still make maybe a buck, uh, and deliver you better security in the outcome. Brian? Yeah, I, I would just say, so we were one of the few people, you know, two or three years ago, we did the hard cut. We, we forced everyone over.

We gave them notice, our account managers met with every customer, and we said, your prices are going up, and if you don't like it, we're putting the product in place regardless of you liking the pricing or not. If you choose not to pay it upon renewal, your cost will go up. And if you don't like it, you can leave.

Now, if we weren't that harsh, but to Ben's point on transparency, and I think this is where I see a lot of MSPs stumble, because your MSP offering, a lot of people consider it proprietary, which we could sit here and argue whether it is or not from a security perspective. We took the belief we did not want to be proprietary with cybersecurity. We, we didn't want it to be something we invented, which is why, Phyllis, I'll keep plugging you like CIS made a lot of sense for us.

We were very open and transparent to Ben's point, here's the stack, here's the cost, here's our cost to deliver that to you. Now, Ben gave me a lot of confidence knowing when we were putting the right security stack in that we had to get out of the mindset of, and if Gary was here, we, we talked about this a little bit last week, rem as it relates to security stack, meaning it generates far fewer tickets and it, it requires far less time to support it if you have the right stack.

So for us and our customers, we are basically a cost plus, plus 20, wherever they were at in terms of their contract upon renewal, we were gonna, you know, start getting up to 30, 35 new customers. We were certainly charging more, but I think the transparency was really key in getting buy-in for them. They saw that we weren't trying to just, you know, use this as a money grab. Our communication to them was, we invested it ourselves.

We understand the risk we posed to you, we were asking you to do the same thing. You need to invest in yourself, understand your risk, and candidly, the risk you pose back to us if you don't put these things in place. So I think when you're, you know, when you're all this fear about getting customers to convert and, you know, telling them if they don't, they're out. Transparency is key. And, and, and don't be proprietary based on something else. And don't be afraid.

Hey, Ryan, Quick, quick, quick question. Wes, I want you to chime in here too, if necessary. I think it would be good. Roll back the time. You know, the MSP time machine is, Jim Lappe says, you know, if you guys, knowing the, the, the role cyber insurance is playing right now, post SolarWinds Kaseya Exchange, would you be leveraging that as well in those conversations? Uh, absolutely. Absolutely. I would, I would know where every one of my customer's cyber renewal is on the calendar.

Um, because as, as great as it is for an MSP, it also can be quite embarrassing in terms of if all of a sudden you get hit with the renewal and you say, Hey, we don't do 50% of this. The, their natural question to them is, why didn't you? Right? So that, that's where I think it's time. Like ms, you gotta get out there and have those conversations. Now, um, I like to look at some carriers like corvus is a fantastic one. They're very transparent on their underwriting application.

They'll show you, they're basically adapting ci IS controls as underwriting, and they'll show you the products that they can map back. Like, I like using that in those QBR as a mechanism to, to kind of tee up the, the conversations like I'm telling you to do it at some point. You're gonna have to, if you wanna keep your cyber insurance in place. So, so Andrew, to your point, I think cyber, the cyber conversation integrated into this is key. Yep. It's your greatest weapon right now.

I can't tell you how many conversations I have every week with clients on the cyber renewal process, and the client has failed and they didn't get, or, or we're just looking at the renewal for the next, the next, uh, the next renewal. And they, they just, they're not eligible, they're not gonna make it. Right? And so here, right here, I'm popping this in. This is fifth wall, these are the five things you gotta have in place.

So, and I just did this at IT Nation literally a couple days ago, Andrew. I said, how many of you guys have all five of these solutions filled and, and selected for a hundred percent of the room goes up? How many of you have a hundred percent of your clients using a hundred percent of these services? No hands go up. So I know that we're in that boat, right? Don't feel bad about that, but I mean, Ryan, you nailed it.

You leverage these things because insurance with the teeth are the ones that are saying this. And this is really an opportunity for you to drive forward. It's, it's so effective and, and you've gotta use it. And if you get 60 days in advance, you're gonna have time to be able to address these for the client. And Ryan, you nailed it. Like, last thing I wanna do is be the one that's embarrassed by the client saying, wait, now I'm not eligible.

And you're like, well, I told you to do these things forever ago. Well, you didn't tell me they were that important. Right? Let's get outta that conversation. Yeah. If, if you take anything away from this call, the, the days of suggesting cybersecurity are over, and I, I would love to sell against an MSP suggesting that, that's all I'll say.

Like, because what if once you get these, these things in place, what you're gonna do when you're in those, you know, first time meetings, you're gonna hand the prospect a list and say, Hey, whoever else you're talking to, just make sure the m ms p themselves has all these things in place. Here's a form. Do they have privilege access management? Do they have EDR? Do they have MDR? Do they have MFA? Right?

And you can just start wedging and selling against your competition who aren't taking it as serious as you. Yep. Alright. Oh, oh, go ahead Andrew. Oh, no. Um, we, Wes, I was just gonna say, I, I, I used the term and, and I'm glad Adam and Cyber Fox do it. They're doing this webinar called the Unregulated Regulator this week. And that's really what I think cyber insurance has finally done, right? I mean, that's really what it is.

I said two years ago in the IT nation keynote, uh, for secure that you'll see, you'll see insurance reg be the, the true teeth in the industry way before regulation. And, and here we are, right? Mm-Hmm. And, uh, we're doing some things even at Fifth Wall that are gonna be very MSP friendly and you're gonna change the future of insurance. I'm really excited about that because that's exactly right.

Alright, so Ryan, I wanna flip to you 'cause we're getting, uh, we're getting low on time here and I wanna make sure Phyllis and Gary, uh, or sorry, Phyllis and and Adam have a lot of time here. Sorry for calling you Gary, you'll have forgive me on that. Oh, I've known Gary. You've been called worse, I'm sure. Uh, okay. So I wanna talk about lead gen.

So I hear Ryan from so many MSPs that like, I can get lots of leads coming in if I partner with some third party, but a lot of times those leads just don't match who I am or I don't resonate right away in the beginning of the conversation. And they don't wanna move. And I just feel like, man, if I just had better quality leads coming in and better qualified, I'd be more effective.

But I know that Ryan, you had a lot of success with, um, uh, security assessments as part of that original lead coming in. Can you kind of talk to us more about that and give some tips for success here on, on what worked for you? Yeah, and I'll have, I'll have Ben jump in on the technical particulars 'cause I'm quite conceptual, so I just did what he told me. Um, but from an assessment perspective, cut yourself little bit. Sure. Here, I, I'll take like one step back.

Our mindset was I want to get to companies who are already thinking like we are now. I think the challenge for MSPs in the SMB space, when you're, you're meeting with, you know, companies who have 20 or 30 employees, they may not be thinking as seriously about security as you are. So that makes it challenging from a, you know, demand gen, lead gen perspective. I'll, I'll just call that out.

We got woken up by the work we were doing in incident response and seeing MSPs get nailed, end customers get nailed. That, that kind of just really reshaped our focus. So Ben, Ben can, um, confirm this. One of the the biggest areas, um, of assessment that is actually really easy for MSPs to do with tools because it's their bread and butter, uh, is around active directory. Um, active directory assessments became a door opener for us.

Uh, we would put the word out among, um, value added resellers that we did active directory assessments. We put the word out among master agencies. We did active directory assessments. That was a great front door for us. The other thing we would do is like CIS, um, like gap analysis assessments on the front end where we just take a really high, you know, high level look at where they're at and where they need to be. Um, but those are the two that come to mind.

Ben, do you have anything else you wanna add? Um, the other thing that got us a lot of attention were specific services around delivering a one product, uh, to customers. So we, uh, launched a managed segmentation as a service, uh, offering, which is something traditionally we had a very good way of doing it very easily. Uh, and that helped us, we did manage identity with Okta and so on.

So we got a lot of customers that came in for single services and over PR leads and we'd convert them into full customers 'cause they'd see how good we were in delivering the service. And so on's. So The OK Directory assessments is one of the best highly recommend checking out Pink Castle. Google it, it has a terrible name, but it's, uh, you can run it for free for non-commercial purposes. Have the client run it. Go for a report, uh, check 'em out.

Yeah, I, I think to Ben's point, so if, if I were to do an analysis of our inbound lead funnel, uh, at the last company, over half of it was from the security product partners that we put in our own stack. 'cause what we discovered is we took, and I, we can get into this a little bit for us as the MSP, we made the decision that we were gonna have an upmarket security stack outside of kind of the MSP ecosystem.

So that led us to work with like the Red Canaries expel, um, Garda cores, illumio's, companies like that. Then we quickly realized that those companies didn't actually wanna work with the SMB when I say that sub 250 employees. So they started throwing all those leads across the fence to us in our geography. Um, then we would get in there and do, you know, an, you know, active directory assessment and certainly try to sell whatever, you know, the, the product was that got us in the door.

Uh, but that, that was one of the ways we opened the door. Awesome. So Phyllis, I wanna flip over to you just in, in, uh, uh, pursuit of time here. Okay, great. Thanks. Um, so Ben, we know that, um, there are many MSPs out there that may not have any security expertise on staff, and hopefully they're working towards that. Um, working with folks like John Strand that will be at, um, write of boom.

Um, so how did you train up your teams on selling your security program or educate your teams On doing so? Ironically, before anti Siphon and the MSP training that John Strand that existed, we did, uh, watch a lot of Black Hills videos. Were just so educational. And so those guys are just great, uh, EV and and every level. I recommend looking 'em up. Um, a couple ways.

There is a traditional approach, the more expensive approach, uh, which you can send people to Sands and so on, but it, nothing Trumps experience. So this is a part where if you're serious about wanting to go fully kind of towards the MSSP route, you do need to make investment.

In our case, we had, uh, we brought somebody in or me more accurately to kind of from a knowledge per perspective, anchor the team and kind of work with the people who were converting from the IT side over to the more security side, the change of mindset, which is highly important. I talked about that earlier. When you're dealing with like a command center technician, the mindset a lot of time they have is, uh, fixing as quickly as I can.

So it doesn't happen again in the most efficient way in security. It's not always that approach. It's not necessarily doing it as quickly as I can. It's doing it the right way and it's not always the most efficient. So a combination of available, uh, online courses sans and really we had teams that would get together when we do incidents. We would bring everybody in in the security team, walking 'em through. So they gained that experience.

We built multiple different playbooks to deal with different situations. So everything is out there in the internet. It just really needs to be organized. If you wanna go to traditional training approach, you can still send people to SANS and stuff. A lot of people come and ask me, Hey, did you do like security comp, security plus and stuff like that. That's, um, not an area I would necessarily, you know, invest, uh, in training up. But all the tools are out there.

And I'd say with Antis, siphon being available, that's a perfect resource for learning security for MSPs didn't exist at extremely affordable rates or basically, Ironically it's going on The, the core. So skills classes literally going on this week, and I'll put it, I'll pop a funny video of John. I mean, if you haven't seen John Strand live, it's literally watching comedy while you're learning about security. Um, I have about a minute and a half of him at IT Nation, which is pretty hysterical.

So I'll pop that in momentarily. And you hears talk about John, he's a very accessible guy. Like you can text him like you don't need to know him. He'll give you his number and you can talk to him, give you advice, uh, just a great person to connect with. Yeah, Absolutely. He was, he was laughing. Um, he was talking to him at IT Nation. He said, you know, it's funny when I walk down like black hat, I can't get anywhere without selfies and everyone talking to me.

He said, at IT Nation, I just walk around. No one knows who I am. It's all good. He's like, I love this here. Yeah, I was gonna say Phyllis to that too, that, you know, everything is relative in terms of size of MSP for us. You know, we got to the point where we could afford to go out and make a security hire like Ben. And with that came all the knowledge and expertise we needed.

Candidly, the training, everything using framework, selecting product, I think, you know, for the owner led the, it's on the owner at this stage. If you don't have the capital to go invest in a security hire, then you yourself need to become the expert. Train one or two folks internally. And as you start winning deals, you know, at some point consider do we bring in someone with that cybersecurity background that can really help us, you know, transition further.

And, and in my mind, I just knew Ben from a, he was very expensive to hire, sorry Ben for saying that, but from a billable perspective, I, I knew through the assessments he was talking about what we were going to do. We are, we are gonna be able to pay for that asset quickly, which, which really, you know, uh, turned out to be true. No, that's a, a great perspective. I I have a follow up to that. I mean, you know, I take security training every year.

You kind of get immune to it and all of that, I mean, 25 years. The NSA can do that to you. How do you get also, I think, you know, so many people are focused on just like keeping things running, et cetera. How do you get that buy-in? How do you have that security awareness, education or whatever on the framework, um, to get the buy-in so that people actually, you know, when they go to sell, when they go to talk to clients, really Believe in it?

Um, well they, we always have a technical resource on the call. So we usually break 'em into kind of two groups. Security engineers, which are actually mostly previous IT folks are doing configuration and deployment of product. Then yet, you know, analysts who are more of the hands-on the buy-in is on. I have not had personally to get a lot of buy-in from the technical folks if I get them excited about it.

So one of the things we did, and I keep talk, one of the very first items we did for people who knew nothing about security is we took active directory, which is something everybody's gonna know on the team. We did an offensive report full, gave it to the team and showed them. What ended up happening is we basically told, all right, go through this report. Here is an attack path that can happen. Learn how it can happen, learn how to fix it. 'cause you're gonna be fixing it.

And by the virtue of learning how to fix it, you're gonna learn why it happens. Once the wheels start turning and they learn about things like pasta, hash, kurbo, roasting, golden ticket, all these items, excitement labels, rocket, uh, from the tactical side, from the sales side, they're excited 'cause they have something new to sell, highly lucrative, they could sell quickly and all the clients want it. So that's at least our, my experience. That's a good question. That's awesome. Thanks.

So, um, Ben, you know, uh, you know, prior to this call Ryan talked about how we're like new besties. Um, he's a fan of, um, CIS on our prior cyber call. Um, he talked about it. So for you, how was, um, using a security framework used in the sales process? You kind of, you kind of mentioned that earlier, but um, you know, for people who are new to this and new to security, like what kind of insights did you have? Especially like, uh, explaining to a non-technical sales team?

Um, so first we, we would go through the, uh, the framework itself with the non-technical at a high level. Um, a lot of them, they're products in there that they've been selling or for many years. So they understood, uh, the mapping.

What I will say when we are going using it for the, as a, as a sales tool, a lot of MSPs don't realize you're actually doing probably 60 to 70% of the controls listed in there, knowing the policy piece, like the actual implementation, like patching, like a single sign-on, uh, collecting logs from switches and so on. Um, so from a sales perspective, they loved it because they can go to customer and say, Hey customer, this, we've done 70% of this already for you.

Here's the remaining item you can do. And so on. I will say this, it's a very common misconception from MSPs that I've worked with that they think that the CIS controls, you need like an outside auditor to perform an assessment of your clients. You're not certifying your client, you're just doing an analysis. A very lightweight CS analysis, honestly is one to two hours. You can get enough out of it to know the direction to go.

And once you gave the, as a sales tool you gave to the rep the roadmap, it says, okay, here's what I have to get the client to adopt. Here's what I have to sell. Here are the products that map to the controls. I have a clear vision what they're missing, what they need down to the list, down to the item. That was extremely powerful and it got 'em bought into it and excited. 'cause it, like Ryan said, it's not an ad hoc thing anymore. There's a map, there's a roadmap.

We're following it here to deliver the services. The technical guys feel good about it because it's, uh, the CIS and everybody knows it. And, you know, it's not, you know, nonsense. The, the non-technical guys love it because it gave them that roadmap. Thanks. And I love the fact that you can show that, you know, over half of it you're already doing. So often I find that, um, organizations are intimidated and they're like, oh God, like I'm gonna have to implement this. This is horrible.

But you, you know, especially as MSPs, you're already, um, supplying so much just by nature of the fact that you have to support an organization Exactly. Have a huge leg up. So I love that on even, uh, typical MDRs in that respect In, Yes. So Ryan, you talked about earlier, you know, you were looking for security minded clients, you were looking for those kind of folks. Um, how did you do that and how did you approach them?

What did you do to, um, do that work to find those kinds of Organizations? Yeah, so for us that it did start pushing us very vertical specific and a little bit up market, uh, candidly. So, you know, we were looking for folks in financial services with a significant amount of assets under management who were already thinking of, you know, of the things that we were thinking about.

And what we identified in those slightly larger organizations was a lot of them were having internal battles on, do we need to hire an MSP and an MSSP? Do we need to have an MSP and an outside MDR, right? So our, our sweet spot became, and if you, you go to Ontario's website, you'll see we ended up calling it an XSP, uh, 'cause everyone just put a X in front of everything. Cool. So we figured we'd do the same thing. Um, was that, you know, if an MSP and an MSSP had a baby, that's us, right?

So we were looking for those customers who had internal IT departments. They may have like a, uh, you know, outsourced like fractional CISO who were really trying to figure out how to navigate these challenges. What we discover and pain leads to sales, right? So we, we figured out the pain that if you are a larger organization and you have an MSP and you have an MSSP, that leads to a lot of finger pointing during the actual problem itself, right?

And what does that handoff look like from an incident to the recovery and resiliency side? So we started going to market as this kind of, like, we cover that entire incident life cycle from, you know, incident open to that resiliency that needs to be put in place to prevent it from happening again. And that, that really opened the door for us. Beyond that, we started becoming comfortable with selling security only as a land.

Meaning, hey, if we can go in there and get an MDR deployment or, you know, get MFA through Okta or something like that, then we can expand back into the IT operations side of the house. So I think that, um, you know, if I, I wanna make sure I, I make sure I provide enough M-S-P-S-M-B perspective as well on the SMB side, you know, we would look for those smaller companies to take it seriously. I mean, that, that's what I would encourage everyone to do.

Like start where there's the least amount of resistance, right? There are companies under a hundred employees who are taking cybersecurity seriously. They're typically regulated. That's obvious with them. We would just sell them on this all in, you know, fully encompass like solution where we cover, here's IT operations, here's security operations, here's how we bring those things together. From a pricing perspective, I would always break it out. Here's our IT operations per seat cost.

Here's our security operations per seat cost. I didn't like doing that, but the reality of who I knew we were competing against was where folks who were gonna come in there and say, we charge one 50 a seat. I'm saying two 70. I want them to understand the differences from a managed service perspective. I'm very competitive from a security service perspective. I'm competitive. Why aren't they doing these things? And this is why we're more expensive.

Um, so I think that's a long way of answer your questions. No, I, I think that's great because, um, when I do go to MSP conferences, they do say, you know, Hey, I'm competing with the guy who's charging $5 less a seat. And so, you know, and then if Gary, Gary pco were here, I think his head would explode. 'cause he'd say, you have to show them. And, and you basically just explained you have to be transparent. Um, and you, and you have to show why is it that you're charging people more.

So, um, I really appreciate that answer. So I think, um, that's enough for me and I'm gonna hand it over to Adam Pico. Let's just real quick, if you could answer Luke's, uh, question about, you know, you know, CIS and what's commercial? It's not commercial. Yes. Okay. Adam, go ahead. Yeah, no, I wanna, I wanna piggyback on that, on pricing, right? Pricing's as good as your service you're delivering, uh, you should never be afraid to charge a competitive price.

Uh, you know, I, I just think, and I'm just gonna impart this a little bit and I want to ask a lot of questions. You know, pricing and packaging, as you guys know, on the other side of it, as we as on the vendor side, right? There's certainly sensitivity to that. The main thing is, is that you're matching, you know, what you're delivering to the cost, right? And then obviously as you manage that, that that ratio, that quotient, no one's ever gonna push you back on you on the price you deliver.

And one of the easiest things that vendors know, because, uh, you certainly see it from the vendors when they raise prices, right? They've done a good job for you over the years, certainly, you know, the vendors and curtain more and more prices and need to raise prices to support that. Uh, MSPs are no different. Never be afraid to raise your price, uh, but make sure you're matching it to, um, the deliverable. And if somebody's in the ecosystem, I recently went through it in Tampa.

There was somebody, I won't call them out who is trying to come in and rip up a lot of MSPs, uh, by discounting 50%. And some of the, you know, the really good MSPs locally, they lost some customers. Wes, how long do you think it took for those customers to go back? It didn't take long, right? Yeah. Just nice little security incident's. All it takes or, uh, you send some email out and you don't get an answer back for like a couple weeks and you're panicking. Yep.

Winning a price is, uh, it's, it's a poor strategy. But with that, you know, I wanna start off with, with, with, uh, Ben, what's really interesting, and I think about the history of, you know, I'm gonna focus a little bit on MSPs, but it really is both, you know, uh, if I go back so many, uh, if I ask what is the typical size of their client, they would say 10 to 25, uh, employees.

Um, I know that you guys had have gone up market, maybe you could share a little bit about going up market, your experience or thoughts around going up to clients that are in that 500 to 2,500 range. Yeah, and I'll, I'll pull, uh, right into this, but, uh, a comment about the pricing, it's for security. That's one of the few areas where it's not a race to the bottom on pricing. In fact, do you really wanna buy the cheapest security you can buy?

Like, I don't think that's a selling point anywhere. She's like, Hey, it's 50% off now, what do you, do? You even know what I'm deploying in there. So, um, I would say upmarket is a very underserved market, uh, area, uh, that generally I feel like traditional, uh, even MSPs and MDRs have a hard time delivering on.

It's an area of a growth where maintaining the entire incident life cycle, meaning going all the way from detection, remediation, resilience to will go, uh, recovery, re-imaging and stuff are areas are usually not well covered by competitors. But I want Ryan to actually talk about this. He has some of the best lines around going the up market, and he, I trust him a hundred percent what he's gonna say next. Well, up market.

I, I just look at, um, like there's a company called Soul Cyber, soul cyber.com. Like they share their pricing right on their website. They're purpose built for organizations less than a thousand employees. They're at like $67 a seat for security. I would say the, the up market conversation where it gets a lot easier is you have, um, very dispersed, you know, internal IT teams and organizations under a thousand employees that they do not typically have a dedicated security hire.

So their challenge is, if I get an incident and someone's on vacation or it's in the middle of the night, like who is gonna step in and handle that for me? Right. Which is very opportunistic for MSPs right now. 'cause that's what you all have been doing for, you know, your, your entire livelihood.

So I think there, you know, our appeal up market at the time was, you know, people are concerned with, with the same things we're concerned about, which leads to finding more pain and then be able to drive folks to sales where they don't, you know, we didn't get into a lot of, um, price negotiation there. And then on the down market side, we, we touched on this earlier. The, the convenient thing for all MSPs is that insurance carriers are making people be serious about it, right?

So we, we have this like outside pressure point coming down. Um, you know, we would always communicate that we're not regulated, you're not regulated. Carriers are gonna force us, but we're gonna impose self-regulation before, before it gets to that point. Um, as a, as a means to really drive those discussions. I'll also add, you know, going up market, one of the challenges a lot of companies have, and I'm not saying there aren't, you know, SSPs out there that serve that need.

And ironically what I'm about to say, it's a lot of MSPs that were MSPs before that serve this need. Most of those aren't looking to just go to an centi or an Arctic wolf, a red canary and expel any of those players. Get their service work incidents they want people to do, manage firewall, managed identity, um, manage your, like, there's a lot more to it that's still security focused that those companies will not touch 'cause it's not a scalable part of their business.

You know, them managing identity, you know, a Arctic wolf managing identity for its customer is not a realistic outcome. They wanna serve as many customers as possible. So there is that opportunity because there are a lot of different ancillary services and security, a a lot of security engineering that most, uh, I would say most MSPs and no MDR R serve. And that's really the opportunity in there. You're offering a complete solution.

Um, and you can also partner with existing MDRs if the client has 'em. It's not like you're losing out just because they're have something already. A a case in point in that. And going back to Ryan, your your point, we actually had an, I can't say which insurer, but we had a situation which a client was trying to get insurance and they had just standard kind of EDR, it's sort of like self-managed.

And the carrier came back and said, Hey, because of your size and complexity, um, you're not big enough to have 24 7 security shop. And so they were asking for a million in, in, um, coverage. And so what the carrier did was they actually came back and said, we'll, sublimate your ransomware to your ransomware payments down to 250 K. And the reason, basically what they were saying was this, look, if you don't have managed EDR, you present such a risk to us because something's gonna happen.

You're not gonna know about in time ransomware is gonna happen. So we're gonna limit our risk by only covering 250 K of that. Uh, and so yeah, we are seeing those things happen already. Yeah. I'll also add one small thing. If you're an MSP, you're probably thinking to yourself, oh, how can I deli? How can I deliver security service? Don't make the mistake of trying to build your own SOC and do put all this, uh, and not, let's say, do a good job and try to deliver that as a security service.

You're better off partnering with some of the established players. Some of the, uh, MDRs that are out there. They're already not gonna compete with you. 'cause they're not gonna do all the pieces I mentioned. They're not gonna do recovery, they're not gonna manage firewalls. They're not gonna go there and make changes to prevent the incident from happening. So it's a very natural partnership between you and some of these established players.

Most MSPs I know don't want to go for the experience of building a 24 7 sock staff to 14 people go by the sea, do all this extra work, um, to deliver. Oh, you know, I'd like to actually just dive down a little bit. I think that's good. And actually bring Phyllis back in a little bit. You know, on the vendor side, Phyllis, right? We are all aligning to the CIS critical controls. If I look at cyber Fox, uh, I know where I align, I align the controls five and six maybe.

I mean, and, and, and bringing the rest of all of us in. Okay, there's currently 18 controls. If you're on the other side and you're on the MS P-M-S-S-P side, do I have to align to all 18? Do I have to support, deliver all 18? No, you, you, I mean you do not. So the, the, um, good thing about the controls, it's not a regulatory framework where it's like all or nothing. I think it's okay to say there's compensated controls or some things don't apply to you. Right?

And so also that's why we also have the implementation groups. Um, you know, organizations need to kind of do this risk analysis on their own. That's why pen testing, for example, even though you can get amazing pen testing for $99, um, we have said that, you know, pen testing really is not for implementation group one. It it's you, you cannot do something if it's going to bankrupt you or hurt your, hurt your business, right?

So you kind of need to do that risk assessment where if the cost of the control will force you to go outta business, then we think that's a good enough justification for you to not implement that control, right? Or if you have a compensating control or if that control does not apply to you. Additionally, there in the ci IS controls, we don't cover like physical security if that is important to you. So go ahead Andrew.

No, I was gonna say real quick, Adam, like, I mean Ben literally just said it about building a sock. If you look at control 13, right? Yeah. There are no IG one, uh, uh, uh, safeguards in it for the exact reason it doesn't make sense for most of us to build our own security operations. So, you know, timely, timely kind of point that Ben made in, in right before yours. Phyllis, would you agree, by the way? Yeah, definitely. Yeah, go ahead Adam.

Yeah, no, I think it's good because obviously it's being talked about so much in the space and people are trying to understand on, you know, where should I align, where should I not align? Uh, I do agree with, uh, Ben's comment. Um, and I think we've seen this going back 20 years, right Andrew, when people were writing their own PSAs and RMMs even, and then understanding there really are some great tools out there, um, to partner with and that, uh, you can leverage those.

Um, Brian a que just a couple salesy stuff that sure I can share. The one that comes up all the time. I'd say every M-S-P-M-S-S-P-I work with that is trying to grow, they always ask, where should I start? Should I hire a sales leader? Should I hire a sales rep? Should I hire A BDR? Should I outsource it? Why don't you share your experience and how you guys grew? You know, maybe talk a little bit on how you did that. Sure.

So relative to size, uh, where I see MSPs have the most success around sales when they're getting started is, let's say you get to, you know, 1.3, 1.5 million and you can afford to go pay someone. What I always encourage owners to do is hire someone that you see as a peer to yourself, right? Because there is a reason your customers buy from you and is that they see you as a business peer.

So this is someone that needs to understand how to have a business level conversation, but catch them early enough in their career where they're not too proud to get on the phone and make a hundred dials a day, right? So I really like the, for a first hire kind of a hybrid inside outside, like it's a little bit of a unicorn.

I've seen a lot of people have experienced hiring people out of like commission only careers like life insurance or people who position life insurance for like business succession planning. Like great people who can drive business level conversations and can be conceptual enough to introduce the things that we want to do. So I would look, you know, compensation matters a lot to people with the sales mindset, right?

So pay someone enough that you can hire a peer of yours that like, and, and to qualify that. Like you would take them to dinner with your group of other IT owner friends. Like if you're in Taylor or you're in one of pica's peer groups, you'd bring 'em along and they wouldn't embarrass you. That could literally be all you need to do from an interviewing perspective. And then set them up with the disciplines to succeed. Meaning there are, you know, probably five major ways to do lead generation.

You know, set them up on a path where they can succeed in each of those categories. So don't hire them without having a house list of customers that you would like to add that they can call on. Don't hire them without doing a project 200 analysis or your, you know, kind of BHAG list. Who are the, who are the greatest customers for us? Don't hire them if you don't plan on investing in networking groups like EO or Vistage or the Association of Legal Administrators.

Like at the end of the day, what we do is very impactful to people's businesses. The idea of just picking up the phone and getting lucky as a means to build and grow your MSP is going to be difficult. So, you know, making sure we have the ability for them to action all those areas to drive appointments is, uh, is very helpful. And what are your thoughts about, like, on how you scaled that, right? So, you know, when you look at that, if you brought that person in, would you then bring in BDRs?

Would you outsource it? And then maybe just as a, a, a subset and either you know, Ryan, you or Ben, you know, what were your thoughts on, um, outsourcing right? Marketing or some of that lead gen Yeah. Marketing. Um, I, I've worked at so many different sizes of msp, so I gotta like pick a hat to wear, you know, in the smaller MSPs, yes, we were outsourcing marketing. Um, we would have the kind of hybrid business development rep who wasn't afraid to pick up the phone.

The next natural, typical hires once that BDR proves he can get out there and generate appointments and close business, backfill him with an inside sales person who gets him more appointments. The minute you go to three, in my opinion, now we need a sales manager who can keep everything on track and, you know, keep having people headed in the right direction. So it, it's in incredibly challenging to scale.

But I think the first hire, the best thing you can do is, is hire someone similar to the quality that the owner themself is. Because they are gonna have to, I tell everyone this when they're making their first sales hire, like block off 50% of your calendar for the first year. 'cause that's how much time it's gonna take to get that person up to speed, right? Manage services as a complex, very difficult sale.

You need to understand the questions to ask in order to uncover the pain, in order to convert. That only comes through time spent with you the owner, right? So I think stage one, find someone that you're not embarrassed to put in front of people, right? Once they start going hire an inside salesperson to support them, generate more appointments and then start looking at sales management and more of the, the traditional route. Yeah, I think that's great.

One thing you called out because the journey always begins with one, right? Mm-Hmm. And so when you look at large companies, um, you know, uh, I had 300 reps at ConnectWise. Uh, it started with one. Yep. Actually that one was before I even got there. It was Andrew and uh, Arnie and Andrew. And then, uh, when I got there we had three and then we had 300. Right?

But I think to your point, it's finding that right person and as you grow and then backing them up underneath and starting to build out a team. And I think the good thing is, uh, MSPs, MSPs, you guys can do it too. It really does start with that journey of one. Yeah. And then, um, and then putting that plan into place and knowing when to bring in that leader like Ryan called out. I think that's a, a great thing.

And then on compensation, uh, maybe any insight that you could share on like what you saw as like a salary versus, uh, an OT with base plus commissions and what you were, you know, what you were paying your sales reps on average. So smaller MSP early days, you know, probably base pay anywhere to 60 to 80,000 with an OTE of the one 40 to one 50,000, right?

And my mindset was for every dollar I'm paying them in salary, I want them to generate the same amount of dollars in new monthly recurring revenue. Right? So that's pretty simple. And then I always liked to, um, encourage the right type of behavior. And here's what I mean by that. When you make your first sales hire, you're going to get inbound leads, right? And we know at some point, you know, closing those leads is equally as important as generating them.

So I like to get creative with revenue sharing. Like, Hey, if that is a Google generated lead for our business, you as the new sales hire will receive 50% of commission on that deal. If that deal comes from the owner and their network, you'll get 50% of the commission. If you generate the deal, you'll get, you know, maybe 110% of the commission.

So I always like to try to put comp plans in place that encourage the right behavior for them to understand no one in this company is gonna sit back, wait for deals to fall on their lap and just get paid. Right Now, if you're putting in the time and the effort and you're helping me in the sales process, great. Right?

And I'll, I'll give you some commission, but when you start sourcing and you build your own network and you get those own leads, I'm gonna pay you the most money on, on those deals. Um, so that, that's the way we thought of it. And then, and by the way Yeah, Go ahead. I was just saying, when you get into the larger MSPs, let's say you have, you know, a $7 million a year budget, hire a killer. And what I mean by that is, I don't want to spend time training them on our business.

I want someone, if I'm gonna shell out $170,000 base pay with $300,000 OTE, then they need to hit the ground running and come to me with a Rolodex, right? And, and that's where those larger MSPs start to have advantage. 'cause they can start to pull people in with the book.

We would hire people out of the cyber SaaS community into managed services sales because they had some of those, you know, more disciplines that you get out of enterprise SaaS and funnel management and you know, Rolodexes and things like that. So I think everything is relative to your size. But I would just encourage you, I I know so many MSPs who get stingy with comp plan, put a comp plan together that encourages the behavior you dream of and then just watch what happens.

And they'll suss themselves out quickly if they're lazy. By the way. Fair and measurable is the key there. Yep. If you bring somebody on and you ask them to create 4 million in ar you're probably gonna be, uh, very unhappy. And they, they'll, they'll just pass through. And then that's a question I usually ask is, right, would you pay $200,000 to create a million in uh, net new ar? Would you spend 200,000 to create 500,000 in new ar? And it is understanding that model.

And by the way, Ryan, you nailed it as, as good as anyone I think I've talked to in a while on the other side. So gospel gospel from him, but making sure that you understand those things. One thing to piggyback off that, and then, and Ben maybe you've seen this too, how long do you see, right?

So as we're selling complex security solutions, how quick do you both, have you seen people ramp up to be able to fully be able to be out there representing your company and being able to actually close business? An individual contributor like a sales hire Yep. Is what you're asking. Yep. So for the smaller MSP single hire, I would give them nine months, um, by nine months we should see them open and close the deal.

What I would tell you in terms of how you, the mindset you want them to have is that I am only going to measure you for the first nine months on your effort. And that's effort I can score, right? So did you do the dials, did you get the appointments? Did you go to the events?

You can control that every single week From an outcome perspective, when we start handing off sales process to that new hire, I'm going to start measuring you on win ratios and close ratios, benchmarking you against ourselves. Um, I'll be, I like nine months 'cause that's how long it took me to sell my first MSP deal when I got hired as a salesperson. So I think nine months. Hey. Hey Adam. Just 'cause we're at the top of the hour. Yeah. I can see. Yep. And I know people have to jump.

Robert, I just wanna say this, if you could before you leave, hey, so, um, one thing we didn't talk about, but we will do a kind of a a we'll carry this forward, but I think it's critical to do daily huddles. Mm-Hmm. You gotta measure every single day what your metrics are. So keep that in mind. We'll come back to that. Thank you to Ryan, Ben, Adam, it was awesome having you guys on, um, our community as always. Thank you for being so awesome with the chat.

Wishing everybody a fantastic upcoming week. I'm not sure if we're gonna do Thanksgiving week cyber call yet. I'll tell everybody, I'll make, make an announcement. Uh, some of us are traveling but uh, again, wanna wish everybody a happy, healthy Thanksgiving. If we don't, we'll be back the following week. But I will communicate if we are gonna do one. Until then, Wes Phyllis, thanks a million. Everybody. Have an awesome day. Take care. Thanks everyone. Awesome. Thanks guys. Appreciate it.

Thank You. Thanks guys.

Related Videos