Skip to main content
Right of Boom
January 30, 2025

Two MSPs share how they built their security practice into their support offering

In this video, Keith Bartol of DKB Innovative and Miles Keogh of Spade discuss the significance of integrating security into managed service provider offerings. They explore the challenges and solutions in creating a security-first culture, emphasizing the need for MSPs to treat themselves as their first client to ensure robust security practices. Throughout the conversation, they share insights on operationalizing security, overcoming sales objections, and the evolving landscape of cybersecurity in the MSP industry.<ul><li>The importance of integrating security practices within MSPs and ensuring clients understand the significance of cybersecurity.</li><li>The role of tools and technology in creating a comprehensive security program, emphasizing the need for proper evaluation and implementation.</li><li>The necessity of establishing a security culture within an organization and ensuring that security is part of the company's DNA and operations.</li></ul>

Guests

Andrew Morgan

Video Transcript

That they struggle with. All right, welcome session 55 from the Cyber Call. And we've got a great show today, joined with two fantastic MSPs. Um, Keith Bartol of DKB, innovative and Miles Keo of Spade. We'll do some intros shortly, but appreciate you guys coming on. It's awesome to have partners with us and hearing from you guys directly. Uh, just a few quick things, uh, up top. I try to get everything out in the open right away. There's links to Keith and Miles is LinkedIn.

There is a link for the, um, threat modeling workshop, which, um, is tomorrow at 1:00 PM This is gonna be amazing. Uh, must, It's a must see, Really, really good stuff. Um, we are gonna have some of the top talent, uh, doing this as well. Um, Hey, so let's just say you can either come to it or you can send us an email saying that you're not interested in security. Either One is. Okay. Yeah, very, very good point. Um, and, uh, so, so that's links up there. I also put it in the call to action.

You'll see in the green if, uh, and share it with others, please. I mean, this is gonna be really, really cool the first time we're gonna literally walk through what it's like to be attacked, how to emulate that attack, why it's important. Um, so we've got Jason Slagel on with us. I mean, Wes Spencer. Uh, we'll, if we have time, we'll talk about that. Uh, but we've got a lot to pack in. I put one of two polls in. If you could just let us know on that.

And regarding the True Methods, uh, free 60 day membership, um, we've got, I think 30 or 40 now that have signed up for it. Awesome. The URL, uh, I just put in there. Again, there's no obligation by the way. This is, there's no like, uh, you know, uh, subversive thing here. It's sponsored. We want all MSPs to engage in it. See it. Um, Gary's team onboards you. It's like you're a real member. Um, it's like $800 worth of, uh, two, two months. So that's there. I put it back in again.

Anything you wanna say, Gary? No, just that's it. Just come in no credit card. No, no strings attached. Just, uh, just content. Both this security track and all the rest of our content we're saying, let's go people. Yeah, exactly. Okay. So let me do intros, uh, miles, why don't I start with you and then we'll head over to Keith. Thanks for coming again, as always.

I think you and I have known each other about 16 years when you and I first met about selling I was your ConnectWise sales rep way back in the day In oh five. Yeah. Oh five. Yeah. Okay. Let us go. Let's go Miles. Thanks. Yeah, so we're, um, that Miles Keo Spay Technology. We're a 20-year-old, uh, which unbelievable hard to even say. But, uh, we're a 20-year-old MSP based just On, what are you, like, 65 now?

I know, dude, I was gonna make a comment about how many grays I have now compared to first, but I don't think I wanna to get into a hair discussion right now. Let's, let's leave that off the table. Uh, but yeah, so, uh, yeah, we have about 60 companies in the area we work with. Um, not so much a vertical, like hard vertical focus, but you know, mostly biotech financial services, DOD contractors, uh, professional services, et cetera.

Um, we got about, uh, about 25 full-time employees and our we pure play MSP. We've been that way from day one, heavy focus on our fractional CIO services and our, uh, auditing and implementation of best practices. So. Cool. Thanks for joining us. Uh, Keith? Yeah, so Keith Bartold, CEO of DKB, innovative. Uh, we're in Dallas, Texas. Uh, we were, we were just talking about it before. So I met Gary nine years ago at SCH NZ Fest.

Um, I was, uh, employed full-time at a, uh, at a company that I won't name, but they are a, a major hardware manufacturer in Texas, uh, that rhymes with a really hot place. And it was a really hot place I was in at the time. And Gary said, well, yeah, why don't you just quit your job and start an MSP? It'll be fun. And so I said, sure. So, uh, we're, I was doing a little bit part-time, but, uh, signed up with true Methods like eight and a half, nine years ago. And, uh, it's been a ride.

So we're, uh, about 40 employees at this point. And, uh, most of our vertical is healthcare. Um, it's about 50, 50% of, of our business, but, uh, all others we've seen a lot in construction and engineering here lately. Um, and so pretty big variety of verticals. Very cool.

And Andrew, what I was gonna mention is when we talked about having a couple people on, I thought of Keith and Miles mainly because they, they work and continue to really work hard in terms of, um, getting their arms around cybersecurity and, um, not just from the technical standpoint, but from the business standpoint. And it's made a positive impact on both of their businesses. So we want, we wanna make sure that comes through today. Yeah. The other thing I would say is just their discipline.

I mean, you know, investing in Pure, I mean, it's not just true Method's membership. I mean, you guys have miles, how, how many years have you been in a peer group now? Since the beginning. I mean, yeah, 10 years. It was 10 years in January. Yeah. Yeah. So, you know, the discipline, the investment of time, energy, talent, I mean, it's, it's significant, but they also run some of the top MSPs from a profitability perspective out there.

So with that, um, miles Talk about Your, you know, security journey, and we've got a lot to pack in here. So maybe we just ki kind of keep it pithy, but talk about, you know, your security journey and maybe a a a key lesson learned. Yeah, I mean, so we're on like version 2.0 of our MSSP offering, and we started it in 2017. I went back and looked like, couldn't believe it was that long ago, and that's when we first got our first customer on it.

And our thought was, we'll get a few customers, kind of figure it out, you know, kind of take the Edison approach, we'll find a thousand ways that don't work, right. Um, rip through security software, ripped through tools, trying to figure out what's, what made a bunch of our horrible decisions. Um, but we, we knew we had, you know, because our MSP was so focused on standards, documentation, and auditing of the environment regularly, it was an easy transition to the security side.

Um, you know, probably one of the biggest things we realized was the, um, the biggest things that we kind of hit was just the, the level of bleeding from the MSSP to the MSP. So like the, the MSSP is finding all the things that have to be done, but the MSSP outsources a lot of work to the MSP, you know, incident response, remediation, like all that.

So you can't really have them as separate, you know, you can have separate roles and responsibilities, but everybody needs to be able play nice together. Mm-Hmm. We just didn't see how much integration there were between the two until you started doing it for a little while. You know? Did you split the, a company, an MSSP office? No, it's a ser it's a service offering of our company.

So we looked at doing it separately, but quite candidly, I think in another two years, anybody that's not on our security platform, it's like, back in the day we used to use a bunch of different backup tools, and now it's like, if you're not on our av, if you're not on our backup, we're not really that interested. I think we're gonna be the same way with security. If you're not on our security, why do we wanna work with you?

So that would be, uh, um, for everyone, listen, like that would be what Miles is talking about. That's his enhanced, you hear me talk about the core offering and the enhanced security offering he's referring to as enhanced security Offering. Yeah. And we're gonna get into packaging and pricing definitely in this today's session. In fact, Keith, I'll just say, Hey, we're gonna break things up today into the journey, uh, operationalizing security, packaging and pricing, and then sales.

So both the existing and that new. Um, so Keith, uh, Keith, how about you? You know? Yeah. Um, your, I would say, I mean, security is very much in our DNA, um, prior, you know, 10, 10 years of, uh, really working with security, working in healthcare, um, doing medical records, conversion and clinical transformation. So really taking, uh, paper to EHR.

Um, and so, so dealing with those early stages of, of HIPAA and dealing with sensitive data around EPHI, uh, and then, and then building a team that had some of those same interests in mind. Um, we really started that way. And it was, it was about, um, about three years ago when we started adding, uh, dedicated roles. We got our, our first, uh, information security manager and really started taking it seriously, um, getting in the tools that were very security focused.

Um, you know, meeting, meeting Wes and, uh, putting perch in about three years ago. Those were the times where I, I think there was sort of a, a, a lot bulb that flipped for us that, um, it can't just be part of what we do. We have to be very intentional about security and, you know, start building goals around that to mature our security and, and, and raise the bar every, uh, year.

And, you know, so that, that, that really just sort of was a snap on to, uh, the best practice alignment and the things that we were already doing, um, using the true methods framework. Um, but things started moving fast about three years ago. Yeah. Okay. Well, cool. You know, uh, let me stay with you and come to my, finish this with Miles, and I'm gonna turn it over to Ryan. Keith, you know, you said it's very much in our DNA.

Can you talk to us about the analogy of, you know, and, and we've done polls on the cyber call here about implementing frameworks within your own MSP, and the results haven't been that great, but, um, they're getting better. Well, They're good for the bad guys. Yeah. Talk to us about, you know, the, the metaphor of putting your own oxygen mask on first, you know, like, Hey, we've gotta secure our own environment.

We have to put methodology and, you know, controls in our own environment, rigor in our own environment, and then go out, so that's culture, et cetera. So, Yeah. Well, I, I mean, I think it starts with a realization that you are your most important client. And so for us, uh, DKB has always been a client, right?

So it, regardless of what tool we're using, um, you know, regardless of our roles, so, you know, we have the best practices alignment, we have A-V-C-I-O, we've always had one for DKB, even throughout our service desk, we treat DKB as a client. And so I, I think it's just, or organically moving that into security side that we have to do security risk assessments for ourselves.

We have to understand where are we at from a maturity score standpoint, and where do we want to be, put those goals in place and then, um, you know, move those over into our annual goals and our quarterly rocks. And if I look back and look over the past three, four years of, um, all of our business planning sessions, every year there is something related to security. And every quarter there's a, there are actions that are related to what can we do to increase DB's, uh, security maturity.

Uh, and then just following through with that, that, and, and so I, I think getting the entire culture and the entire company aligned with going security is not kind of important. It's really important, and it's one of the rocks that all of our departments should be moving together to, to move up. Um, like it takes that sort of discipline. I really love the fact that you said you're the most important client and that you are a client. That's, that's a great takeaway. Miles, how about you?

Very similar. Yeah, very similar. I mean, it's, um, you know, I would add to that the one thing, the result, one result we got out of it, but we didn't really think would come out of it is, um, a lot of the best practices that end up implementing to make you more secure, actually make you a better MSP. So, um, we found like there's some things that, you know, change control process and, and how you're doing those notifications and having a good incident response plan, all that kind of stuff.

Um, it's, as much as we do it to check the boxes on the security side, and I hate using that term, but that's kinda like, Hey, we gotta make sure we have these things for security. It's actually a good best practice, right? So we found a lot of times where like, oh, we don't have great change control process on this. And because of that, we saw higher levels of ticket counts, things not being done correctly the first time.

So we started putting the change control process in, and we actually made our MSP better. So it's kind of cool little outcome that we didn't, we didn't expect. Very cool. So, Ryan, when I thought about handing the ball to you and operationalizing security, I, you know, every time I think of your, your words, like, we don't do anything without good inventory management. So I just thought operationalizing would be right up your wheelhouse. Yeah, sure. So we let you take it from here. Yeah.

By the way, I, I am gonna steal with reckless abandon, uh, client zero of an MSPs themselves. Uh, I think if you think about it that way, it, it really kind of starts to enforce the level of service that you need to have when you're thinking about securing yourself. Because often MSPs take more care of their customers than they do it themselves. So that's a great talk track. I'm gonna steal that. Like, yeah. Wow, that's great.

Um, so yeah, certainly I think you knows, but, you know, securing yourself is one thing. Um, and obviously securing your customers is something else entirely. Um, you know, we've talked about it takes people process and technology to do that. Um, you have to fund through it, um, you know, based on consumer pricing and the packages you sell, sell. So let's step through it. I'll start with Miles.

When you think about building a security program for your customers, what role does standardization play in that from a standardized process, standardized technology, um, standardized offerings? Like you said, you've, you've gone through the school of hard knocks and you know, you learned how to do it the wrong way five, 15 times before the right way. What, where did you land with standards in that?

So, you know, we focus on small to medium business, um, and we have to, we have to be able to apply technology in a way that, um, and security in a way that meets the requirements for them, mitigates their risk. But it is also consumable by small to medium business. You know, our clients, our clients aren't gonna spend 25 grand a month on security, right? It's just not gonna happen.

So, um, you know, we always explain to them part of the reason, like, if we do ever have conversations about the standards we wanna put in place, or they wanna make any tweaks or customization, part of the conversation is, look, we're able to do this at a price point that small to be businesses can consume, because we have standards across all of our clients because we're following the same frameworks, right?

And we do have, like with ours, and I don't wanna get into packaging and pricing too much, but we do have, you know, kind of the offshoot of, okay, they're A-C-M-M-C client, so they need this, they need our standard plus this, you know, so you can do a little bit of that to make sure you're meeting their, the regulatory requirements. But, um, you know, the standards are what allow us to do this stuff efficiently and, and, um, you know, be able to adapt to that small to medium environment.

Um, and obviously, you know, almost all the controls are based around having those standards in place. Okay, perfect. When you think about staffing for building out the security program, right, because staffing is difficult on many levels, um, you have the war for talent, which we hear all the time in security space. Um, you have, you know, the, just kind of the, the enterprise space competing for these, uh, these assets drives the price up.

When you think about securing yourself, securing a customer, how do you think about staffing and, and like these dedicated protective roles for your customer and for yourself? Sure. I mean, uh, and I think Keith hit on this a little bit to start, it wasn't dedicated, right? It was we're the MSP was loaning people to the MSSP, right?

So MSP was loaning people to the security group to kind of do those things, but we kind of looked at it as we sort of took, um, we kind of broke it down and said, it's almost the same as that. For those, you know, familiar with the true methods framework, it's sort of very similar to it, right? Instead of a VCO, you have a vso, right? Similar, similar roles. The big differences, I always say the VCO is an enabler, and the VSO is a disabler, right?

Um, you have a, you have your, someone doing your technology alignment piece. Um, on the security side, you have your, you know, security manager, right? Someone who's doing the implementation, vulnerability scanning, that kind of stuff. Um, your SOC versus your noc, and then the client, the help desk sort of acts as that point of if there's an incident, right? So we looked at it and said, what can we, what can the MS SP outsource to the MSP?

And we said, okay, any incidents that happen, go to our client care center and our technology alignment engineers on the managed services side will do the remediation of things on vulnerability and stuff like that. The CO role was the one that we really felt we had to get a dedicated person to. Um, 'cause as you grow and scale, once you get enough clients on board, that really needs that dedicated role, right? So we just looked and said, okay, great.

We have our, we have our people doing the technology alignment, make sure they have the capacity to take on that security function and build it into the rhythm. So now, you know, you normally would do this, but because they have our security offering, you now have to do these additional things, these additional audits, these additional documents, this additional process, and make sure those triggers are in place for things like projects, right? You're putting in a new piece of technology.

You can't do projects in a non MSSP client like you do in an MSSP client. So, So again, uh, you're using that term MSSP, but it's setting off a flare of people and emotions and reactions because they just assume you have your, that you are your own sock, your own seam, and you're, you're not. So I think he's using that term and it's, for us, it means like a security first MSP, it's the enhanced security offering. Yes.

But when you put that moniker on it, it's sending off flares to people and they're asking tons of questions. Yeah. It's our security add-on. Yeah. Security add-on you outsourced your sock and scene. Exactly. Yep. Yeah, Just keep doing it miles so you can, while up the entire group Don't Yeah, I got, I got triggered hard on that one. So yeah, I think We have, we have support works, which is our MSP, and then we have a Security works add-on, so I'll refer to 'em as that now. Yes. Right.

So Keith, over to you. Um, you know, I've, I've, I've worked in security programs, uh, large publicly traded companies, um, and they're very different depending on the culture of the company, what you build, how you build it, the success of it, how long it takes, um, all comes down to culture. How did you create a security culture in your MSP? Like, what was it that, was there, was there a mandate? Was there a set of values?

Like how did you really establish it as something more than just something we're gonna do to drive revenue? Like how did it become part of who you are, part of that DNA as you said? Yeah, I, I mean, look, I, I think it starts with the interview for people. I, I, I mean, that is a core criteria when we are hiring people in any sort of technical role is do they value security or, uh, everyone has that client, right? That, uh, they don't want to be interrupted by security.

And security is just an afterthought, and it's just don't hassle me with that. Uh, um, you will not get a job at DKB if that's your attitude, right? Like, like you, you have to value that, and you have to understand it, um, and have that enthusiasm and getting people, um, in leadership roles, be it VCIO or, uh, what we call our VCTO, which is our technology alignment managers, uh, they really embrace security. They have it in their background.

Uh, it, it's a field that they're excited about and like they understand, um, the need to be secure. They understand the value prop behind it. And so like when they're, when they're interacting with our team or they're going in front of clients, they're not having to put on a mask and pretend that security is important. Well, because my employer thinks that important, that's important. I'm gonna pretend like it has to be part of who they are.

Uh, and, and then we just encourage that and we create an environment where, um, we reward the, the, the thinking around security and, and we have fun with it too. You know, I think about our internal phishing campaigns. Uh, we have a lot of fun with our security te team trying to phish me and phish everyone in the organization.

And sometimes they're successful and then they, they celebrate it, and there's just a lot of banter that goes back and forth, but, um, like we, we make it part of who we are. Okay. Cool. Um, I would love to chime in on that, but we got a lot more to get through. So the, the last topic is very near and dear to me. Um, the role of tools and technology, um, yeah, I've been known to say, do not bring in technology until your people in process are figured out.

So what, what role did you find that tools and technology have played in your journey to becoming a enhanced security? MSP Really, really important. And, uh, you know, tools aren't one size fits all. You really have to look across your client base and you have to look for your own needs. And that, that makes it just a difficult task at hand. Finding the tools that will meet the needs of, of the vast majority of, of your client base.

Because if you start, you know, in the interest of standards, we want to pick, ideally we want to pick one tool that fits a certain need and it fits all of our clients. Uh, that's tough. And so I think being very rigorous in that technology selection is important. So we have a, um, technology selection committee and, uh, our CISO sits on that committee, but also our, um, our proactive alignment.

Uh, people sit on that committee and, and, um, and then we have representation from our service desk, and they're very intentional about going through the checklist and vetting out those technologies and making sure that the first customer that uses that technology is DKB, uh, and really putting it through the ringer. Um, I, I mean, I think of what we did with Perch and we put perch through the ringer for months, just hammering it and using it in really difficult use cases internally with DKB.

And then, you know, our, our, the second customer beyond DKB, was a client who had very complex needs and a lot of demand on it. And our thought thought was, well, if it works for DKB and it works for our most complex client, then it'll work, you know, for the majority. Um, and so it's just like anything else. It's discipline and a rigor to make sure you've got the, the right pieces in place. Did you wait on your tools and technology kind of pathway until you had people in process?

Or did you, did you, did you tackle all three of them in tandem and like, I guess what I'm looking for here is a war story of like, I brought in technology way too soon. Um, right. And this is what happened, and man, I'm never gonna do that again. Like, do you have any stories like that? Uh, yeah. Well, I, I, I do. In fact, um, I, I, I'll go, I'll, I'll go back to to, to Perch. Before we found Perch, we were on a, a SOX or a SIM platform.

We thought that we could sort of bring in the SOC piece in-house and figure it out our own. And we brought in a, a tool set, um, that, uh, just did not work for us. Uh, it was complicated and we just got in over our heads. Um, and it was very painful because I think we, we sort of jumped on the bandwagon and thought, we've gotta have this and we've gotta have it now. And didn't evaluate like we should have. Uh, you didn't have your, you didn't have your culture yet. You didn't have your role.

You didn't, you weren't ready for it. Right. That, that's exactly right. Um, on, on the other hand too, I think the, the other danger, the flip side of that is paralysis by analysis. Like, you can get too deep into figuring something out when you need to act on it and move. And we've had, we've had clients where like, there is a need for a technology and, you know, don't waste good crisis like that.

That necessity brings about innovation to where you gotta get something going and you gotta rally the team behind figuring out this technology and, and meeting the solution. And, and, and I would say there are times where, yeah, we're, we don't put the process in place and get the documentation in place like we should ahead of time, but it comes, it kind of comes in parallel, uh, on, on a fast track. And so there's been a little bit of both. Can I just make a quick comment?

I love what you said Keith, and what Wess and Ryan are saying, you know, and we've talked about Sun Neil, you and his RSA presentation talking about enterprise software was the number one thing. And it was, was typically around things like sim because of lack, lack of process, Gary, and, and turning it over to you.

Let's, uh, Well, I'll, I'll, I'll jump in and I'll say this too on the tools and technology, kind of where we're at now and where we wanna be is, um, sort of what the healthcare analogy is. Like, you know, that there are these elements, right? And we, we, we run across these same different scenarios with clients.

And so now we're trying to figure out what is the treatment plan ahead of time and, and what are the pills, uh, and figure that out because we know that we will run into clients that have x, y, and Z type scenario. And now we're trying to get ahead of it. It, it wasn't always that way. We, we operated like the ER early on and, or, or more like, you know, here's a, here's a new, uh, here's covid right now we all gotta jump together and come up with a cure.

Uh, but we're trying to work ahead now, uh, for, for what the prescription is. Well, you did say your, your folks don't just put masks on. So that's a good segue to Gary. Yeah. So, uh, I'll start with miles on this one and, but I want Keith to chime in on, 'cause this is really important. So at some point you have to make a decision how to go to market, right?

And so first you have to decide what's gonna be from a security standpoint, what's gonna be in my core offering 'cause of certain high level of security that anyone who does business with your company, right? Then as you mentioned, there's enhanced things that you just know that maybe 25% of your customers are, are gonna need based on their business model. So the first thing is how, and some things you might sell a la carte, 'cause Keith and I talked about this.

You haven't figured out the, the costing on them yet. So how do you first figure out, make those decisions about trying to pack as much value into the core offering as possible? So we started with, uh, the regulations that we were dealing with, right? For our clients and what's, what are the requirements of those regulations? So, um, again, we had a lot of DOD at this time.

It was DFARS, now CMMC, but we know time we were focused on the DFARS requirements, some, um, SEC and some of the biotech space. So we looked and said, what are their requirements? What do they need? Um, and we came up with our, our enhanced add-on, right? Like for these customers only because these are things they need solely for the regulation. And by the way, we're starting to see people finally do this because it's the right thing to do.

But when we first started doing this, the only people that would sign up for this were people that had to do it to be in their industry. Right? It wasn't, it wasn't because they wanted to do the right thing. And that's changing now. It is, yeah. And, but what we did is, as we ran with that, um, the first year, I think it was right after the first year I told you what we did. We went back and looked and said, wow, we gotta take all this stuff. There's a bunch of things that we saw.

Our security clients had a much, uh, much better performance, much lower risk. We're like, let's take these things and move them down. So they're part of our core offering. And we ended up, we went to our clients, we moved all these things down, and they're probably about four or five items that moved down. Um, we told 'em we're increasing their all in seed price by 11 bucks on average, you know, to cover the cost of it, and this is what we're gonna do.

And we had one client that emailed to ask some questions. We had no one that complained and we got a ton of thank yous because they saw it as, Hey, you're looking out for us. Appreciate it. They see what's going on in the news, right? I remember that quarter. Yeah. You had 40 or 50 customers at the time and you got a hundred percent acceptance. Yeah, It was crazy.

So, and so every year we do that, we just look and say, what do we have in our core offer on our enhanced offering that we should bleed down? And then what are the ad hoc things we're selling to people that we should make part of our enhanced offering? Yeah. So we're always chuckling those, you know? Yep.

Keith, you and I have had this conversation and I know there's a few things that aren't in your core offering that, um, one, you talk about maybe how you set a minimum and you're doing some things on an a la carte basis because you don't know what the ongoing cost to be able to turn it into monthly recurring revenue yet.

Yeah, I, I, I think, I think there's a, there are a few things that we're doing it and just doing it hourly or doing it remediation because we just, we haven't done it enough to develop that rhythm to fix fee. And I, I think there's gonna be anybody starting out and and bolting on security services, they're gonna run into that. And so you really have that choice of, am I gonna do this for my client or am I just going to let a competitor come in and take this business?

Well, no, you're, you're, you're gonna do it. You just have to do it in a way to where yeah, maybe you're, you're, you're not gonna get great margin on the front end on the first time. Um, you're, your, your client is, is gonna be waiting on you and maybe you can't do the best job, right?

But you're gonna try to get 80% and document and have lessons learned from it and have very frank conversations with, with your client, especially if they have something that's unique, uh, that, Hey, we're gonna work this out. Like I'm gonna dedicate this time and I think it's gonna be this. If you'll work with me, um, we'll, we'll get there together. You, you do, you do some hourly type work and I'll la cart work.

Then the most important thing following that is you break it down and go, what type of people do we need to have doing the work? What is the, how many Customers could they do this for? What's our cost per c Gonna be? Yeah. You start building out the SOPs around it and just dissecting it and then you can cost model into something repeatable that hopefully the majority of your clients will benefit from.

Uh, and, and then like, uh, miles said, you eventually, uh, maybe that rolls into your offering and it just becomes part of your standard. Gary. Yeah, For your next question, I wanna set this up for you 'cause I think it flows in Well, Ben, put in a question. Lemme just extrapolate, to what degree are you integrating security awareness training into your security offering?

The reason I wanted to posture that for your next question, Gary, is, you know, as an example, sometimes people layer in know before and then put like, Hey, this is a phishing, you know, there's a phishing button. You can put an icon. I know MSPs where that's turned into a secondary spam filter. No disrespect, Ms. P uh, know before does a great job.

My my point is, there's an incident where a situation where seemingly, hey, you need security awareness training for certain regulatory requirements, yet it added on and one MSPI was talking to 30 plus hours a month investigating those additional things, miles shaking. Yeah. Yeah. You know what, let me stay on this train of thought.

But that, but in general, not that specifically, but understanding the impact that people aren't associating the labor costs associated with technology, they figure the margins out on. That's that Keith. But one thing I wanted to ask you first is, um, and then I wanna answer a question that Julian asked, uh, ear earlier about why would you even have an enhanced offering?

Why wouldn't you, you know, I, I'll take a shot at that one, but first, gimme an idea three or four years ago, what your average, the range of an average seat price for a customer for your core offering, and then what is it today? How much has it changed in the past three or four years? Yeah, I, I, I think the average seat, and if, if we're talking, let's say it's a, a, a 50 to 75, uh, seat client, right? Somewhere in that range I, on on, on average, we've seen it go up, um, 25 to $50 a seat.

Yep. I would say is about the range. Uh, I, I'll say this though, it, it, with security, it becomes much more complicated to price these things out. And it, and, and really the per seat pricing, I, I don't wanna say it goes out the window. It's a good average and to look at the health. Um, but here's the problem is that I, I may have a core set of rhythms that I have to do in a set of tools, right?

I've got, I've got soc sim, I've got vulnerability scanning, um, I, I've got some enhanced, enhanced EDR or, or, uh, you know, some, some sort more complex tool set. Um, if I've gotta go through all those rhythms and I've gotta do a security risk assessment, and then I've gotta keep that alive on a quarterly basis. I've got a, a fixed cost, and it doesn't matter whether you're 10 people or whether you're 200 people, I may have three or $4,000 that I have to charge for that.

And that's just the way it is. And so, obviously charging $4,000 for a 10 person company, that's a, a lot tougher sell than it is for the, the 200 person company. And so our, our seat prices, they kind of go in the ranges to where when you get a little bit bigger, it doesn't affect your seat price that much, but I've got a few clients that are $500 a seat and you look at and go, holy moly, well that's 'cause they're small. Yeah. And they need and they need it.

So I think that's why I asked you that question. 'cause you and I have had this conversation several times that there's certain things that you just mentioned you're gonna do that have a cost and it doesn't change dramatically from 10 to, you know, may not change dramatically from 10 to 50 customer Stuff. It makes that conversation really difficult for the small clients. Like, or easy below, They, they either get the, they see it and get the value, or they don't. Yeah. Yeah.

But below the, the, we have much more success in the, uh, I wanna say 40 plus seat clients from a security conversation. Then below that it, it just gets tougher because they start looking at it per seat and they go, oh, it's 250, it's $300 a seat. It's just tougher. So you have to reframe 'em and do a little more work on the front end just explaining it. So, miles, when we met, you know, you, you know, I always gotta say one, at least one embarrassing thing every time we're together.

But when we met way, way back when, you know, in days of old when men were bold, um, I think you were about, what, 80 to a hundred bucks a seat. Your, your goal for me was to get me to $85 a seat. And so what's that range for your core offering before you add on the security stuff? Uh, our core offering is about 180 5. Yeah. Right. So, Yeah.

So what I want people to hear is, you know, if you know your math, it, it just having, you know, having, before we talk about some of these enhanced things that Keith and, and Miles are talking about, like that's what it costs to secure a customer.

So Miles, when you go in and talk to, and I know, and I'll use this as the transition over to, to Wes and some sales questions, but when you go out on a prospect and you find out that they are thinking about security, they are a good fit, but they're paying, you know, 20 or 30 or $40 less on average per seat, um, how does that make you feel? Uh, you actually get excited about it? 'cause it's a great time to help someone out, coach 'em a little bit, right?

Um, I always joke around and say there's three types of people in this world, people that believe in math and people that don't, right? And it's like, you sit down, you talk to these people and say, you're getting all this, this is what you're paying. You know, can I tell you what our approaches be and, and why it would be impossible for us to do that for that price. Yeah. And really, so I'm trying to, I always use that term weaponizing your competitor's low prices. Is that how you look at it?

Yeah, absolutely. Yeah. And we've literally, I've had conversations once a little side note, but it was funny. Some DOD contractors, I've had two conversations over the past four years where I talked them out of the working for the DOD, we, we got to the end of the discussion. It's like, you know what percentage of your, your business is with the Department of Defense? They're like, well, like 10% and it's over less profitable.

I'm like, well, if you don't want to do this, maybe you just shouldn't work for the DOD anymore. You Know, it's almost like an Ms P. You almost have to be the customers if your customers gotta be all in or not. Yeah. You can't put one foot in that the same way. You can't do all those things for two customers. Yep. Like, you have to be all in and use it as a reason for people to do business with you or don't do business with those customers.

So I hope every, uh, uh, everybody, I hope everybody is hearing that. Right. So, Keith, is there ever a scenario when you're not much more expensive than what they're spending now or the competitors Very rare. Yeah. I mean, we, we, we are surprised when we come into a situation and we're, you know, at similar cost. And, and it is usually just because they're out of negligence. Like they've just ignored it and they've got this mixture of in-house and outsourced and just nobody's watching it.

But in almost all cases, yeah, we're gonna be more, and that, that's sort of a trigger, uh, for me and my sales team when, uh, when you hear a prospect say, well, you know, this just doesn't make sense because I've got somebody else that is offering the exact same thing and they're 20 or 30% less. Well, and you know, Michelle on my team's like, whoa, whoa, whoa. Okay, you can go and you can get cheaper and that's fine, but don't tell me that it's the same thing. Right? Like, come on.

And, and, and that's where you come in and you just gotta go, Hey, you know, you can go for the, the, the hatchet, but this is what the chainsaw costs. It just, it is what it is. And you're going to get a different result. Yeah. Both can take a tree down. Exactly. Exactly. But you can't say it's the same thing. Don't tell me it's the same thing. Listen, I just, I just made a decision that I'm, I'm opening up my next MSP in Dallas and we're $501 a seat.

So look out, move over, Keith, you're coming with that. Let me, let me send it over to Wes. Gonna ask a few questions about, about sales. Well, you're too late, Gary. 'cause I'm at 5 0 2, my friend, so, you know. Hey, Keith, can I, Keith, can I put you on the hot seat? The sales hot seat? I think I'm already on the hot seat. Oh, We bring it on? Yeah, sure. It's, it's getting hotter.

So those of you that know me know, um, the sales angle is near and dear to my heart just because I feel like most MSPs, when they're honest with themselves, have had to learn this whole thing of how do I run a business? How do I actually sell it? What does like marketing and branding look like? All these other things that are ancillary to success. We're really good at technology, but the people and human components sometimes come second.

So, uh, for, I guess maybe the first question, Keith, is can you just kinda touch in a little bit on like who communicates in your org, the changes to security? Who communicates that to the end user, new clients, all that? Is it only you? Is it only tech? Is it everybody across the board? How does the communication angle work for you guys? Uh, I, I mean, so for existing clients, it's primarily our V CIOs and the, the V Cs.

And so we have three at this point, um, really take that lead, um, from myself and ciso, but I, I would say it even starts a little bit before that with, um, our v CTOs, the technology alignment professionals that are out there because they're having, um, those monthly meetings and visiting with our clients. And so they're sort of setting the stage and teeing things up.

And more often in our co-managed clients, um, you know, their point of contact is gonna be the IT director or, um, maybe it's a service desk lead if just somebody technical on their side. Um, but they're gonna have those conversations to go, Hey, like, this is really not secure and this is out of our best practice alignment and this is why. Um, and then, you know, the VCIO comes in and sort of relates it to the overall business and the strategy.

So it, it starts there and then it kind of trickles up. And then, um, often the VCIO will, um, sort of tag me in if, if, if they're not taking the message, if they're not taking security seriously or, uh, or it's difficult to sort of posture it, um, then, then I'll get tagged into it. This goes back to something I'm going off script, Gary, go ahead. Because I gotta get, Andrew, I'm gonna get a tissue. I'm listening you guys, I'm getting a little choked. Isn't that awesome?

This goes, I'm going off strip script for a minute. So I advise a few young startups, and one of the things I always tell them, Keith, and you just said this in different words, I wanna say the same thing and see if you agree, is sometimes they'll be like, yeah, I gotta go find the sales person that's gonna like go and take us to the next level. I'm like, no, you don't. You already got 'em. They're like, well, where are they?

I'm like, you, you are the number one salesperson in your org as the owner operator, you must be, you can never expect someone else to be able to sell and promote and pitch the way that you must be able to as, as the owner. I mean, do you agree with that, Keith? Have you seen success there? I miles to chime in on this too? Yeah, yeah, please. Absolutely. I mean, I, I, I have a, uh, full-time outside sales resource, Michelle, she's awesome.

But, uh, she is going to tag me in to help with that message, right? So, so yeah, you, you have to, it's really a team sport. Like sales is just not a, a one person thing. And from, like I said, with, with existing clients, it starts with the day to day interactions. Uh, and then it funnels up to me with, uh, with new prospects. Um, I get tagged into it. So it's a, it's a teamwork. Miles, what are your thoughts? Yeah, it's, um, I've gone the path with outside salespeople.

We have inside sales, um, we've always had inside sales, but I've gone the path with have, you know, sort of outsourcing, not outsourcing, you know, having someone else do that role besides me. Um, the fact is, and, and I look at sales as not just new clients coming on board, but getting people onto our enhanced security or just getting people to buy into changes in our security process, right? That's a sales process. Same thing. Our fractional CIOs go out, they have the conversation.

Um, but there's, there's something about business owner to business owner looking 'em in the eye and saying, you know, dude, I'm do worried about the same things you are and, and this is what we're doing internally and I'm putting the extra effort and time and resources into it, and this is why, um, there's something in invaluable about hearing that from another business owner. And, um, it can certainly speed up the process a little bit too. Sure. Yeah. I love that.

And, and it's just, I've seen the same thing, you know, from the days of perch, right? And, uh, something I've, I've definitely learned it's a good takeaway for everyone on the call today, is it it does start with you, especially if you're the owner operator. If you're not, um, still you have a role to play. So, Keith, I wonder if, um, we can sales role play a little bit. I know Gary loves to do this, I love to do this. So talk to me. Give me some Keith words.

Uh, talk to me like I'm, I'm a client. I'm either using you, I'll let you go whichever way angle you want. Either I'm a current client, it's time for me to do more, or, you know, we're talking for the first time and you're pitching services. Walk me through how the conversation sounds, walk me through how you talk about it, how you pitch it. Give us some of your, uh, words of wisdom here.

Well, I'd say like, if you're a current client and, um, you're, you haven't had to invest in security in the past, then I'm gonna start with just like, let, let's, let's talk about what's going on in the world. Like, unless you've had your head, head in the sand, you know that the security thing is kind of a big deal. And, um, I I, I hate to break it to you, but it's a big deal for you too.

Like we're, we're managing your it, we see what data you're working with, um, because we've had those conversations. We're, we're sitting down and you're meeting with my VCIO on a quarterly basis, and we're understanding how important your business is. And we've, we've had sort of those business impact conversations. Uh, I, I would just say it this way is, um, you pay us to tell you straight right? And, and give you hard truths.

And I'm saying that I care about you enough to let you know if you're driving towards a cliff and there's fog in the way and you just can't see it, and it it the same way going into the doctor's office, right? I'm sure doctors don't find any joy in telling their patients that they have cancer. That is not a fun conversation in a healthcare setting.

However, it's my responsibility as your IT physician to let you know that that stomach ache that you have, it's not gonna be fixed just with Tylenol that the chemo and the radiation's coming and it's gonna be painful and it's gonna be very expensive. But the consequence of not taking action is lethal. And we've been working with you a while and we understand your business. And I I'm telling you that if I were in your shoes, I would be getting treatment because the alternative looks pretty grim.

I, I hate telling you that. Don't think that I'm trying to sell you. Uh, I I'm just having an honest conversation with where you're at. And, um, so don't, you know, don't shoot the messenger, but that it, it it is what it is. And, and I didn't create that cancer. Um, but I'm here to help you change it And, and listen right there, you know, what your customer's gonna say 'cause I wanna say it. You're talking to me and I wanna say, Keith, what do we need to do? Right?

How can someone not say that when you have that, those words you just gave, that's really awesome. Sorry, Wes. No, no, that's good. Yeah, I mean, I'm just, I'm going through this in my mind as well. You know, you went from the threat landscape overall to specifically the threat for this customer, helping them realize it's a real issue. You went directly into, you know, an analogy that helps them understand this of like, it's the right thing to do.

It's not just that I'm selling you, but it's the right thing that I, that, you know, and I'm not alone in this, right? It's not always an easy conversation. You know, David Powell and I often call this, you know, the birds and the bees conversation, and it can be a little like that, you know, the first time you have to have that conversation with the kid on the truth of, of life, um, you have to have that with your clients and it doesn't come naturally. It doesn't come easy.

No one's born with the capability and insight to have those conversations. It comes through practice. So I mean, I I think that's really good. Um, US and shared risk was in there. Yeah, that's right. But that analysis is just, is a great, it's great that analogy because it's like, it's not my cancer, it's yours, it's not my security risks. It you, it's yours. We are here to help you manage it, man. That's right. Right. You have to want to do it. You have to want to, to get that done.

So, uh, really good. Sorry. No, you're right. And we, we have to help our clients under understand that you can't outsource that risk. You know, they, they want to point their finger when something happens. Anyway. Okay. So, um, maybe one other follow up question, Keith, give me some, how are, what are the responses? Like, uh, do you get any kind of like major objections that you're always going through? I'm sure they don't always just say, well, you're right a hundred percent.

Let me just do everything you say without question. Right? So gimme some responses back. Yeah, I, I, I mean, I, there is pushback and I think I, I think a, a lot of pushback will get, well, gosh, it, it just feels like whenever we talk to you guys, you're just trying to sell me something. And I, I, I think going back to reframing 'em and, and saying, look like we care about you, and if you want to go somewhere else for the security portion of it, like that's fine.

But, um, my job is to offer you the treatment plan. That's my responsibility. I can't force the pills down your throat and there, and, and there's a cost for 'em. And, and so, you know, just I think continuously showing that that care, that I'm not just trying to line my pockets here. Like, we are your advisor and we're gonna have hard conversations with you that you're not going to like, and I need you to be okay with that.

And I need you to, I need you to hear me on that and not think that I'm just going after revenue. I, I love it. And don't you feel like the whole VCIO process gives you the credibility to say, I'm not just meeting with you to sell you something once a quarter, but I'm actually adding value through the way. So when I come and say, you gotta do something that's gonna cost more, it carries more weight. Do you see that as well? Absolutely.

You have to, you have to establish that relationship upfront. And if you have clients that, I, I'll say this, where we've had clients where that VCIO relationship was, was broken, and we just weren't able for them to let the walls down and, and make us a trusted advisor, um, that been much more difficult. Uh, and you know, we've, we've had a few conversations where that it did not go our way.

You know, we had, uh, I I, I remember it was a few months ago, we had A-V-C-I-O conversation like that with, uh, with a doctor and basically saying, look, these are the things and these are the things that you have to remediate and, and these are the things that you have to put in place, or we gotta get a hold harmless letter or something in place because your healthcare, and I'm just saying that like you're breaking the law.

You're willfully negligent because your plausible deniability has gone out the window after we've, we've provided this and, you know, we got a, a termination letter, uh, the next day. But I looked at it and went, what would've happened if we hadn't had that message? It would've been a lawsuit, is what would've happened. Would I rather lose a client or be fighting a lawsuit for a client that you don't really want in the first place?

Well, it had to come to an end and it was better that it would be through a termination clause and not in court. So, yeah. That's good. And, and I know we got some follow up questions for Miles as well, and Make sure you ask him ballpark, how much MRR new MRR they've added in the past year. Throwing a little shade, Mr. Pika is what, what we're doing here. Uh, but, uh, wise words for sure.

Uh, yeah, so maybe in 30 seconds, Keith, can you kind of just chat a little bit about what that thin red line is? You've alluded to it a lot, like there's a walkaway. Do you, is there like a certain thing that's always the walkaway? Is it a gut feel? What's the walkaway look like? I, I, I think so I think it's two different things that I, I, I, I'll, I'll echo what Miles was saying is that every year they, you know, evaluate and these are like some minimum standards.

And, and we did that in a few areas, uh, at the beginning of this year, um, and said like training was one of 'em is that you either have to already be paying for training or get training. We just need to check the box that you are, you are training your people and you're not just saying that you're training your people, like show us the logs and that this is happening. If it's not happening, I'm gonna offer this to you. I'm gonna increase your seat price.

Um, the only way out of that is either we don't do business together or you sign this hold harmless. And the reality is, is if you're willing to sign that hold harmless, we're probably not gonna be doing business together in the future anyway. And, and, and so I, there there is a, there is a sort of a thin red line like that I, and I think in certain situations though, it's also uncovering what those clients, uh, what they're doing.

Like we found clients where they have really, really sensitive information that they're emailing back and forth. And when you do just go, okay, time out, right? If you don't have MFA and you don't have encryption in place and DLP policies in place, like, we can't work in that way. Uh, and so you're gonna find those things where you have to say, that's a huge red flag and that's a showstopper. Uh, and then you, you have to be gutsy enough to go in and have a hard conversation.

And that's different for every client and every situation you run into. Yeah. Just add one thing. One thing that we're able to do now that we weren't able to do six, seven years ago is with the NIST framework, the top 20 critical security controls, all those things becoming so public, we don't, it's no longer we're selling you this solution, we're selling you these goods.

We can just say, look, this is what the, you know, international standard of what you should be doing says, this isn't my opinion. How do you want to address this? Do you want us ignore it? What do you wanna do? Right. Kind of putting in an airplane. I love it. Yep. Yep. Ryan, back to you. Yeah, so I'm gonna, I'm gonna condense my, uh, my questions into, into one or two. I'll have it be a free for all between the two of you.

And it's more about, it's continuing the sales conversation, but it's more geared towards, um, prospects. How are you identifying prospects? How are you, how are you bringing them into your pipeline? Um, how has that approach changed and how has your selling motion changed over the past several years as security has starting to heat up? And, and how is, how are those changes facilitating your ability to attract new prospects?

Because it's one thing to have a difficult conversation with a customer that you've already built trust with. It's an entirely another thing to, to, to have that conversation with someone that you're still forming a relationship with. With Yeah. As far as finding them, um, and, and kind of getting 'em into the funnel, we started looking at the verticals that we have experience in regulated verticals.

Um, we also looked at people that maybe some of the verticals we didn't have as much experience in. We just had one or two clients in that space. We applied our, our enhanced security offering, did a little case study on it, and then we kind of target those people. Um, and then we also look for industries that have change in security.

So, um, whether it's, you know, in New York rolled out there, enhanced security policies when it was went from DA to the CMMC, um, some of the changes in biotech, we had some local changes here in Massachusetts, you know, be the first to get that information out there. You know, really trying to show them that we're on the ball on this and then, you know, our normal, our normal sales process, right.

You know, dialing these people, sending 'em marketing information, trying to get in front of 'em. Um, you know, it's, it's definitely different when you're doing that with someone new than someone that already trusts you. So typically what I do when we go through is just ask them about how they're handling it today. Like tell me a little bit about your process today. What does it look like?

You know, and, and hit the different areas from everything from backup disaster recovery and business continuity to, um, other parts insurance. Yeah. Yeah. And insurance. The other parts of their security. And, and then ask them some simple questions once they're done. Like, look, so when you're sitting down once a quarter and going through and benchmarking where you are as far as enhancing your security, what are you doing it based on who does that with you?

You know, how often is your MSP out here going through that stuff with you? What does that look like? Usually they don't have great answers. Yeah. I'd say very, very similar for us. And, and I mean spot on with what Miles was saying, is, um, I think we, we try to determine upfront how important is security to this prospect, right? And are, are they regulated? Is security, uh, related to contracts? Do they have to have it? And, and sort of like we started off talking about culture of security.

What is the culture of security, uh, within the company that you're selling to the prospect and with that individual person? And then, um, yeah, There's a, there's a really important concept in there, which you're talking about, which, which I call bad revenue, right? That that customer that doesn't care about security, that isn't living your culture is bad revenue, right? It's like the doctor, uh, that, you know, didn't want us sign up old harmless.

So how often do you actually fire a prospect in the sales process yourself? It, it happens. I mean, like I told you, I talked two people out of those two people I talked out working with the DOD weren't clients, you know, we were going through the process and it's like, look, if you just think you're gonna check a couple boxes and you're gonna be good to go, it doesn't work that way. And we don't wanna be part of that, right?

'cause they're gonna check the boxes and it's not gonna work out well from the end and we're gonna be the ones left pulling the bag Back to you. Ka. Well, thanks Ryan. Miles. Keith, that was fantastic. Thank you so much for coming on. I, I, I, seriously, it was really great to get your perspective right, you know, from a real world perspective of what you're doing, et cetera. Quick mention next week is July 4th, so wishing everybody a fantastic week, uh, and weekend long weekend.

So we will be taking that off and back the following week. Gary, any closing thoughts or comments? Yeah, just, uh, what I want people to hear today is, um, I could bring 20 other people right on that are having success. The one thing they all share, um, that these two professionals share is that, um, they understand their business. They're professional business people first, technology second. And it's really hard to make this turn.

If you just know technology and you don't know how to run a good business, you're, you're, you won't get there. I hadn't seen anybody, uh, get there in, in a scalable, profitable way. So put the time and energy to really start. You hear Keith talk about he can't do it all. He had an annual plan, he had big initiatives every quarter. He broke it down into things he knew he could accomplish. That is a common thread across every security first MSP that's having, and they are having great success.

This is good business, uh, for not just the people on here, but for all the people that can do that. Yeah, great point. Okay, so last thing I'll say, aside from having an awesome week, awesome, uh, holiday is the threat modeling workshop tomorrow at 1:00 PM Please, uh, make it please tell people it's, it's, uh, it's, it's pretty awesome. So we're Threatening you to go Take care everybody. Make it a great day. Okay guys, thanks.

Related Videos