The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/the RocketMSP Podcast
the RocketMSP Podcast artwork

How to Talk About Cybersecurity to Clients & Prospects with Mark Lamb from HighGround.io

the RocketMSP Podcast · 2024-06-05 · 47 min

0:00--:--

Key moments - from our scoring

Substance score

62 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence12 / 20
Conversational Craft12 / 20

Mark Lamb, CEO of HighGround and M3 Networks, discusses the critical mindset shift required to effectively sell cybersecurity to SME clients and prospects. Rather than leading with product pitches, MSPs must adopt a consultative approach rooted in understanding the prospect's business goals, constraints, and risk appetite. The conversation emphasizes that SME owners - typically opportunistic entrepreneurs - make risk decisions differently than enterprise counterparts; they weigh security investments against revenue-generating opportunities and often dismiss threats they haven't personally experienced. Lamb advocates using frameworks like NIST Cybersecurity Framework 2.0 (which now includes governance as a sixth pillar) and tools like Exercise in a Box from the UK's National Cybersecurity Centre to make security risks tangible and specific to each client's situation. The episode covers practical questioning techniques for discovery (email quarantine reports, MFA adoption, endpoint detection tools), how to connect financial and reputational risks to actual business impact, and the importance of positioning the client as an active participant in risk management rather than leaving them to assume the MSP handles everything. Trust, patience, and leaving frustration at the door emerge as essential soft skills for moving prospects toward informed decisions.

Key takeaways

  • →MSPs must slow down and understand client goals before selling - the battle is won or lost in the discovery phase through consultative listening rather than locked-and-loaded pitch mentality.
  • →Connect security investments to business outcomes (e.g., expansion into China) rather than leading with abstract threat statistics; clients choose risk mitigation when they see how security affects their strategic goals.
  • →Use frameworks like NIST Cybersecurity Framework 2.0 and Exercise in a Box to make risks visible and specific, so clients experience the realistic impacts of incidents rather than dismissing generic financial figures.
  • →Ask specific discovery questions (email quarantine, MFA usage, endpoint tools by name, content filtering) to quickly assess security posture without needing to install agents on prospect networks.
  • →Position the client as an active participant in governance and risk management - not a passive buyer - so they understand which risks they're accepting and what the MSP is mitigating on their behalf.

Guests

Mark Lamb

Topics in this episode

Multi-factor authentication (MFA)Endpoint Detection and Response (EDR)SentinelOneGovernance and risk managementNIST Cybersecurity Framework 2.0HighGround.ioM3 NetworksExercise in a BoxEmail quarantine and filteringSME vs. enterprise security posture

Questions this episode answers

How do you explain cybersecurity importance to non-technical SME owners without overwhelming them?

Connect security directly to their business goals and revenue-impacting risks rather than leading with technical details or large threat statistics. For example, if they're expanding internationally, show how security risks could derail that expansion. Use frameworks like NIST and exercises like Exercise in a Box to make risks tangible and specific to their situation.

What are the biggest misconceptions SME clients have about cybersecurity risk?

They often believe they're too small to be targeted, that large attacks are unavoidable anyway, or that security spending should wait for next quarter. They also underestimate financial impact because average breach costs (e.g., $1.5M) are unbelievable to them. Many have become desensitized to security news and resigned to the idea that attacks are inevitable.

What discovery questions should you ask a prospect when you have no technical visibility?

Ask about specific tools and capabilities they know they have: email quarantine reports, multi-factor authentication (do they enter six-digit codes?), endpoint detection tools by name (e.g., SentinelOne), VPN or remote desktop usage, and content filtering (do websites ever get blocked?). Four or five targeted questions will clarify whether their security posture is solid or weak.

Why do SME owners prioritize revenue opportunities over cybersecurity investments?

SME owners are typically opportunistic entrepreneurs who got to where they are by taking calculated risks. They weigh security spending against hiring another sales person or other revenue-generating investments, so they choose growth over risk mitigation unless they personally experience a breach or see a direct threat to a business goal.

How does NIST Cybersecurity Framework 2.0 help with client conversations?

NIST 2.0 now includes governance as a sixth pillar, emphasizing that clients must actively manage risk rather than assuming the MSP handles everything. Aligning the prospect to the framework shows mature thinking and helps them understand their own role in risk management and which risks they're accepting versus mitigating.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains solid practical advice on consultative selling approaches to cybersecurity, particularly around understanding customer psychology, risk-based decision framing, and using frameworks like NIST. However, there's considerable repetition of core concepts (customer doesn't care, education > sales pitch, align to business goals) across the 47-minute runtime. The substantive new ideas - Packs and Tracks framework, using cyber insurance policies as discovery levers, risk registers at onboarding - are valuable but sparse relative to filler.

The conversation begins, or I should say, where the battles won and lost is before you go to speak to your customer about security.
If we can make them realize the risks associated with that, and therefore the impacts, and how that can derail the successful expansion into that region, or how it could destabilize what they've built already, they can start to realize why this is necessary.

Originality

11 / 20

While the Packs and Tracks framework and the cyber insurance discovery technique show some original thinking, most of the core advice - consultative selling, aligning security to business goals, using storytelling over statistics, building trust - is well-trodden in sales training. The frameworks referenced (NIST, Exercise in a Box) are established best practices, not novel insights. The episode lacks contrarian takes or first-principles thinking; it largely validates standard MSP sales methodology.

It's the way you do your business, the way that you're going to work with them in partnership to take them on this journey.
Packs and Tracks

Guest Caliber

14 / 20

Mark Lamb is a legitimate operator with 14-15 years running an MSP (M3 Networks) and built a product (HighGround) in the cybersecurity space. He has hands-on experience in the problem he's discussing and speaks from genuine customer interaction, not theory. However, he is also the vendor selling a solution, which introduces bias. He's not a top-tier enterprise CISO or industry researcher; he's a solid mid-market practitioner.

My background is actually technical. We, me and my business partner set up an MSP in Scotland called M3 Networks about 14, 15 years ago now.
I have lived through, I continue to live through the problems that you experience and face that customer face to face in a real meeting

Specificity & Evidence

12 / 20

The episode includes some specific examples (China expansion, healthcare/legal verticals, dental practices with HIPAA obligations, Exercise in a Box framework) and concrete questions to ask prospects (six-digit codes, DNS filtering). However, naming is sparse on actual company case studies or metrics. The $1.5M breach cost, $20K insurance policy, and inflation discussion are mentioned but not anchored to research or specific customer wins. Many recommendations remain abstract.

For example, say the customer is Goal is to expand the business into China.
Do you get an email quarantine report? Several times a day or once a day.

Conversational Craft

12 / 20

The host (Steve) asks coherent follow-up questions and occasionally pushes back (e.g., asking about differentiators, budget, which technology to prioritize). However, follow-ups are often surface-level; Mark makes sweeping claims ("only 14% of people remember stats") that Steve doesn't challenge. The host allows Mark to dominate speaking time and doesn't probe contradictions (e.g., Mark warns against fear-mongering but then endorses using insurance non-payout as urgency). The conversation is friendly but lacks intellectual friction.

Yeah, I gotta say, getting annoyed with clients is really easy to do, and I'm gonna share something I probably shouldn't.
So help me out here. just came up with this one. Nobody's ever thought of this before, I'm sure of it.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

customer44risk30understand26cybersecurity25security22trying17budget16risks15insurance15sure14clients14different14sell13customers13money12cyber12

Episode notes

Mastering Client Conversations: Selling Cybersecurity with Mark Lamb In this episode of MSP Tutor, host Steve Taylor is joined by Mark Lamb, CEO of High Ground and M3 Networks, to discuss the strategies behind selling cybersecurity services to clients. The conversation covers topics such as building trust, the importance of an educational consultative approach, and understanding clients' needs and budgets. Mark emphasizes the role of storytelling over statistics, the use of frameworks like the NIST Cybersecurity Framework, and how to handle objections and misconceptions. The episode also highlights the importance of aligning cybersecurity with business goals and utilizing social proof to validate services. Essential for any managed service provider (MSP) looking to improve their sales and client relationships in the cybersecurity domain. Learn More Learn more about Mark Lamb on LinkedIn Check out HighGround for smarter cybersecurity conversations with clients and prospects.

Full transcript

47 min

Transcribed and scored by The B2B Podcast Index.

Welcome, everyone, to MSP Tutor, the show where we want to teach MSPs something useful. We've got no sales pitches, vendor agnostic material. It's going to be something that you can use no matter what stage you are in in your business. So without further ado, I'm joined today by Mark Lamb.

Mark is the CEO of High Ground and also of M3 Networks, if I, understand correctly. Welcome, Mark. that's great. Thank you, Steve.

us a little bit of background about you so that way I want them to know, like, why should we trust Mark? we're going to talk today about selling cybersecurity, and want to make sure that they believe what you have to say. Yeah, well, hopefully you can trust me. Yeah, so my background is actually technical.

We, me and my business partner set up an MSP in Scotland called M3 Networks about 14, 15 years ago now. And, for the longest time I was the CTO, technical director and founder. it was only in the last five or six years that I sort of transitioned from that to, the CEO role and I've been building out HighGround as a product to help MSPs, deal with the cybersecurity problem. So, that's my sort of background.

Definitely more of a creative technical person, they want to And how you describe that, you know, two sides of the brain are connected, which is immensely frustrating at times, but I would suppose to the point of thrust, I would say I have lived through, I continue to live through the problems that you experience and, have to face that customer face to face in a real meeting, and really sell that stuff that, and get them to understand the problems and get them to make Decisions and also deal with it.

When they don't and they leave, they leave us with the problem instead, and you're left wrangling with that problem too. We're going to talk today about having a conversation with clients and prospects about cybersecurity. The end goal is to sell them something. I'm of the opinion that you need to educate, instead of sell, and, allow that prospect or client to make an informed decision, and almost come to their own conclusion that, hey, I need to do this thing, is this something you can do for me?

Maybe that's why I was never great at sales. What's your take on that, Mark? Yeah, I mean, you are right, because if you go in there all guns blazing, with an agenda that you're going to sell this stuff and the customer's going to buy it they're going to be a white knuckle ride as they're petrified about what's going to come next and how scared they are. It doesn't go well.

The customer's just shut down. And so this educational, you know, consultative approach, which is typical of us as MSPs, right? It's always been, I think it always will be a consultative sell in what you do, which means education is naturally a part of that. But I think the conversation begins, or I should say, where the battles won and lost is before you go to speak to your customer about security.

And actually, I suppose this is true for anything, but in security in particular. I think you have to understand that it's not us, as the MSP, it's not our place to judge the customer and where they are, right? The customer, it's our job to inform them of where they are and of what the risks are, position cybersecurity as a business risk, advise them on what we think they should do and help them to identify what they need to do because there'll be lots of things that they have to do, don't want to do, but have to do.

Which we'll probably come to later, and then support them to make that decision and do that consultatively through education, through guidance, but not to have an agenda that they must buy this thing, otherwise it'll break your heart because they'll probably not do exactly what you want them to do. Is there like a process that you found, works more often than it doesn't? I think so, yeah. I mean, I think you've got to go in there with a mindset of like, I'm here to understand.

You've got to start back in that place where, You're trying to understand what the customer's goals are, what any of their constraints are going to be, what their triggers are going to be, recapping the past, I think that's a key thing, you know, like taking a walk down memory lane. I think as MSPs, we're always so keen to want to go in there and sell the next thing because our world moves fast. Right. And, I'm sure everyone's world moves to a certain pace, but I really do believe that in IT, our world moves faster than most people because of the rate of change.

And we're used to change. And we go into these meetings with customers locked and loaded, ready to do these things. And the customer wants to kind of meander down a path instead and talk about, what they've done in the past, how we got here, what that thing is that they bought, why things aren't working, so on and so forth. We've got to be prepared to do that.

So I think often we have to, we have to slow down. We have to try and understand and get on the same page with them. I think there's just so much tension and friction in some of these customer meetings because the both sides want out of it is broadly the same. But their approaches are very different and they clash and that's what I see more often than not.

And it takes somebody to have to take the reins and that approach, that process that you talk about, it begins with going in there with a completely different mindset. And I think that you have to leave the frustration at the door. No matter how many times you've been here, had this conversation with the customer, being annoyed with maybe decisions that they've made, you've got to leave all that behind. Because if you take that into your meeting, it's just going to be even worse.

Yeah, I gotta say, getting, getting annoyed with clients is really easy to do, and I'm gonna share something I probably shouldn't. So I treat. Like my family, unfortunately, kind of like clients in a way, but unfortunately, because they're family, they don't get filtered correctly. My filters off.

So, if you've ever watched Saturday Night Live, there was that, gosh, it was 20, 30 years ago. The IT guy, MOVE! Like, he would just be so rude and abrasive. That is unfortunately how I am with my family, and I think that's how I would want to be.

with my clients. So with that said, how can I effectively communicate, the importance of cybersecurity to my clients without sounding like too technical or overwhelming them with a plethora of information because I found that that's what I do with my family is I overwhelm them with things that doesn't necessarily concern them because I get excited about the tech and that's my biggest problem is I'm excited about the tech. Yeah. Totally.

I think you made mention to it, slightly earlier on, I think the way to go about it, the way to approach the conversation with the client, is understanding, first of all that they don't care about buying cybersecurity. In actual fact, I think you could probably say that for most things we sell them. Like, nobody set up a business and says, I'm going to set up this company so I can buy lots of IT and spend lots of money on all this stuff that I could rather be spending on whatever, right?

Return on investment to stakeholders. In most cases, in SMEs, it's having more money for myself, I think if you go in with that mindset and realize that you have to understand that customers look to you as a trusted advisor to take care of and advise them on what to do. And I think that the frustration comes from us. Get an annoyed that they are now not listening to what we're saying to them.

So we're your trust advisor, but you're not, you're not listening to our advice. So do you really trust us at all? And a lot of frustration comes from that. So understanding that actually what we need to do is come down to a level where we can tie this to the customers, Goals, Objectives, Risks, Requirements, Compliance, why compliance is so good?

Because we can tie it to somebody else. Everyone wants to blame somebody else, right? Say, well, such and such tells you you have to do that, so you've got to do it. Customer will often say, well, our back's up against the wall, have to do it.

Because I've got no choice and everyone wants the decision to be taken away from them. So they have to do it. I think when you leave the customer with the decision, they'll just choose not to do it. So we have to somehow achieve the same thing that compliance achieves.

And often that way is to be able to draw that line of sight from what they're trying to do with how that matters in security. And if we can connect the dots for them so they can understand that, then they can make risk based decisions. So for example, say the customer is Goal is to expand the business into China. Okay, and it's IT people now, alarm bells are ringing in all, corners of our head about, oh my goodness, me, all the things that we have to think about now because of this.

The customer does not think, oh, so China, I better do something more with cybersecurity. So we come along, we need to do this, but the customer's thinking, yeah, Mark, but I've got to spend money on. All this other stuff to open an organization in China. And the last thing I want to be doing is spending even more money on security.

I don't think that's important. But if we can make them realize the risks associated with that, and therefore the impacts, and how that can derail the successful expansion into that region, or how it could destabilize what they've built already, they can start to realize why this is necessary. So security just becomes a, it's not buying security because we want to buy security, or even because we need to. We're buying it because It's going to affect the outcomes, the goals that we're trying to achieve.

Does that make sense? I gotta say. Traveling to China, like, while I would love the idea of going to China, it terrifies me because I think as soon as you arrive, all of your electronic devices that you've brought have been hacked. Yeah, I've not been to China either, yeah, so, what are some of the common misconceptions that clients are going to have about cybersecurity?

You said that. They're not going to look at this as important. I want to kind of dig into this more, like why don't they think it's important? what are those misconceptions they have that are giving them that false sense of security?

I think there's two sides to this. The first one is the obvious ones that we've probably all heard people say before, right? It's Yeah, I'm, I'm too, I'm too small, it's not going to happen to me is the one I assume. Yeah, exactly, too small, not important, they don't know who I am, then you've got the more firm objections like too expensive, we'll do it next quarter, we'll do it next year, I'm not doing it unless somebody makes me.

All these kinds of things. It's just resistance, pure resistance. They don't want to do it. And it comes down to like, it's the same thing with the media, right?

We listen to so much of the media that eventually we become completely desensitized to it. To use a sad but real example, during COVID times, we would read the news and for the first few days and weeks and the number of deaths there were, it was devastating. And then somehow, a few weeks later, we The number just becomes, oh, it's only that today, but you forget these are real people in real lives, right? And you become completely desensitized to what's really going on.

And security, cyber, has become very much like that. You know, we've seen so many people being attacked, so much money being lost. Eventually, people start saying, well, you know what, if those guys can't protect themselves, what chance have I got? And then it becomes, they just stop.

They stopped even thinking it's believable. They don't even think it's achievable. They just resign themselves to it. And that's dangerous.

But there's nothing really we can do about that, other than obviously try to make them realize that they don't need to make heroic efforts in order to, make it happen. You just need to do the basic good things right and that they shouldn't, give up that fight. But the second side of it that I think a lot of people don't really recognize and it's a thunk. I think it's the fundamental difference between the enterprise and the SME space and that is that in the enterprise people build Relatively mature organizations that are governed, that have got compliance, that people are running that business as professionals in their jobs, so they're appointed by stakeholders and leadership and they run that business in a certain way.

In the SME world though, you're dealing with a very different type of owner. You're dealing with opportunistic entrepreneurs often. Businesses that are held privately by the person that can make the ultimate decision don't have the level of management, almost definitely don't have the level of governance and risk management. And so, you're free to What you're actually being weighed up against is not, should we do this to mitigate the risk?

And in those people's minds, they're thinking, if I spent that money on another sales guy, I could increase my revenue by X. So what do I do? Do I go for the opportunity or do I mitigate the risk? Am I going to, these creative, entrepreneurial type people want to charge ahead.

They're not typically worried about, they got to where they are by taking risk. Right. And so they're not sitting here thinking. I guess that they, they think they're a little bit more untouchable than the average company or the average person.

And so. all sorts of crazy decisions get made that we can't sometimes compute why they're not understanding this risk. It's not because they don't, it's just they choose to make, take a different decision because they think that it's not happened to me and it plays into the first thing that we talked about which is it's not going to happen to me or I can't stop it anyway. I'll deal with it if it happens.

So screw it. I'll do this other thing instead. you mentioned risk, so let's talk about that for a moment. there are like two big types of risks that I can think of that clients should be worried about, and that's financial and reputational.

I'm sure there are other types of risks, but those are the two that I think would resonate well with these non-technical folks. How do we explain that potential risk to them in a way that makes sense to them, that resonates? I think that when it comes to financial, we do need to try and steer clear of talking about the big numbers because they're not really believable. I mean, I've been in real conversations with customers where I've said the average cost of a cyber attack is going to be like 1.

5 million. And the customer laughs and says, well, I don't have one and a half million, so, it's not going to cost me that. And that is really difficult. So we have to try and make those financial costs believable to them.

So we have to, comes back to the earlier point about understanding how their business operates and how they make or lose money. And so we need to try and tie it to Real numbers and often times most businesses will not be completely dead in the water, especially now because of hybrid IT, infrastructure, you know, back in the day when there was lots of exchange servers on premise, you know, if your network went down, your email went down and the world was came to an end, whereas now, in the UK, we have a thing called Exercise in a Box, which is a framework by the National Cybersecurity Centre.

You can get it on their website, but it's quite a useful tool to approach both of these things. And it helps, what, it's essentially, taking the executive team through a real incident and having them really think through what's happened. So it's like situational awareness, really thinking about the implications of, oh my goodness, this has just happened. So it's okay to say, Steve, your reputation is going to be in pieces if this happens, but words are cheap.

But if they go through the experience themselves by working through the realities of what's happened and how they're going to recover, it's much more impactful for how they're going to learn and remember that. I suppose the essence to both of those things is you need to make both of the things really believable by making it specific and unique to them. is there like a framework that you use when you sit down with clients or prospects? And I guess I should further, ask, do you talk to clients differently than you talk to prospects?

So let's start there. Oh, that's a good question. When you talk to prospects, of course, you're trying to understand, where they are today, and that's actually arguably more challenging because they often don't know where they are either, they think, oh, well, I've got this thing and we've got MFA turned on and you're treading that line between trying to say, No, you don't have what you think you have, and it's definitely a difficult thing to do. But in both cases, it's about trying to make things visible and understandable.

So the NIST Cybersecurity Framework is a fantastic tool for that. And if you can align where they are today to the NIST Cybersecurity Framework, all the better. And some of you watching this might know that they've just released version 2. 0.

So there's a new version of that framework, which has previously had five pillars. And now they've got a sixth pillar, which is governance. And they've moved quite a lot of the controls around, but governance is all about a lot of what we're talking about here which is helping the organization to really understand their position and manage this as a risk. So, a lot of actions must be managed by them and they must have active involvement in it.

They can't just think that the MSP alone is somehow going to just solve all the problems by buying technology to solve it. That's, not going to crack the issue. So then that works on both sides, right? So talking with prospects, they're often more open to that because they're in that phase, you know, they're talking to you because they're maybe unhappy with who they're with.

And so they're kind of getting a grip on where they are, what they need to do. Peace of governance by trying to manage the risk, manage the problem. With these existing customers, that can be a bit more challenging because they just think you're doing it all ready, and you're trying to open up that subject. So using a framework definitely helps them understand that there's a lot of thought going into these things, and their best practices.

is there like a framework or a set? I always go through this order of operations, when talking cybersecurity with people. starting by understanding, Where they are now and their role in that, so understanding what they are, and if you use the cybersecurity framework, if we tie that into what we've just said, right, so identifying what their security risks are today, identifying what their needs are, what they need to achieve, protecting against that, so buying security solutions and services, or selling security solutions and services to your clients that meet those particular needs, desires, and the customer's appetite for risk.

ensuring that they can respond to anything that happens. And that doesn't mean a complete incident. It also means just any activity, whether it's good, whether it's a false alarm or not. Being able to recover from that and being able to learn from that.

And with the application of, NIST 2. there's also the govern piece, which has managed and governed that risk over time to make sure that the customer, we'll use the word customer here, the framework really talks about governing risk from within. as an organization, but we could use that as a customer and say the customer should be involved and understand their appetite for risk, understand their risks they're taking, which risks they're accepting, which ones they're going to mitigate, and what the MSP is doing for them in order to achieve that so that they don't just think that we're doing it all.

And if you go through that journey with your cust Customer by approaching it through a position of understanding. Is it the matters to you? What are you trying to achieve? How can we align this?

We can take care of most of that ourselves as MSPs without having to expose the customer to the whole framework and the whole journey. Got it. When it's a prospect, you need to ask, a lot more questions because you don't necessarily understand their current cybersecurity posture, especially, some MSPs want to install their agent and glean all The information they can glean and doing a technical discovery that way. Other MSPs don't want to put anything on a prospect's network until there's a signed agreement for liability purposes.

not here to argue which of those methods are right, because I think there's merits with both. But with that said, when it's a prospect, you don't necessarily Crespo Roman, and I'm here to talk to you about how we can help you know all the things, right? Especially if you're doing this agentless, and you're going in there blind, and you're only getting the information from the prospect. can you give me some questions that we should be asking every single time we sit down with somebody new?

if you can get it, I would be asking for a copy of an existing invoice that they're paying a provider for. That's a big shortcut, but that's hard to get and the trust has to be there. They're not always gonna wanna pass that information to you cause they might think that you're going to then price based on what they're paying. but that is definitely useful I have this opinion that we can just figure everything out when we turn up, look at computers and somehow determine what's going on and there's friction there, because the MSP is careful.

They don't want to end up, signing themselves up to something that they don't know what they're getting involved in. I would, definitely start with asking and understanding, what products and services they might know the name of. So things like, do you get an email quarantine report? Several times a day or once a day.

That can have a good lead into whether or not they are using an email filter or email protection tool, Are you having to enter six digit multi factor codes or respond to alerts on your phone when you try to log in? Yes or no. That's going to give you an idea of whether MFA is turned on or whether it's just I've never seen a six digit code in my life might tell you, okay, they don't have that turned on, right? Especially now with the massive boom and MDR on endpoints, maybe using some common product names.

Like are you familiar with, give an example, like SentinelOne for example. Customer is likely to have heard the name of some of these tools being mentioned by the help desk of companies they're working with. So mentioning product names can sometimes be helpful. And same thing goes for firewalls and things like that.

Asking them if they're using, if you know that they have servers on site, you might say, are you using a VPN? Do you use remote desktops? So using some of these keywords that trigger the customers, oh, we've got that. These are all very useful.

Gain content filtering. Do you ever get blocked pages when you try to go to websites? Or can you just get onto anything you want? Oh yeah, we can get onto anything.

You know, there's nothing that's stopped us. Four or five questions in. Steve, you're going to be pretty clear of how good or bad this situation is looking, and you 60 seconds. cybersecurity in place.

They're getting services from one of my competitors. How do I differentiate my cybersecurity services from the competitor? Because let's be honest, this is becoming a heavily commoditized industry at this point where there's a very low, barrier to entry. Anyone can be an MSP.

You don't have to go get certified or a degree or anything. And, more and more often, it feels like the tools are doing the work for us. So how do I differentiate what I'm doing from my competitors in the area? Yeah, and I think the answer to that question, it's really simple.

It's you. You are the differentiator. It's how you do your business. Because you're right.

They're always going to sell the dream, sell the product, everyone that's going in there along with you because they're likely not only talking to just you they're probably talking to two three other providers as well you're very conscious of what they're saying and it's always going to be led in on the products the customer then ultimately just can't actually tell the difference. The difference has to be you. It's the way you do your business, the way that you're going to work with them in partnership to take them on this journey.

Pay homage to the fact that, this is a journey, it's not a one and done thing. You're not just going to buy a product that's going to solve all your problems. And what we sell you today is going to have to change in 12, 18, 24 months. You want to be doing that with a partner you can trust.

It's going to give you the right advice and go on that journey with you. And we are the people to do that, not because we're going to consult with you. We're going to help you understand. We're going to understand your business and we're going to make sure that we're, selling your products, services, That you need and that you're not wasting budget because let's be honest You've got lots of stuff to spend your money on in technology and everything else.

Then it comes down to that trust factor Anthony in the chat said, something I agree with completely. A number of clients, or prospects for that matter, will only consider a cybersecurity strategy and implementation during the inflection point of an insurance audit. Have you seen that across the pond? I agree because it's that point we made earlier.

My back's up against the wall. I have to do it now. And if I don't have to do it, I won't. So then how do I create a sense of urgency around cybersecurity without resorting to fear mongering and FUD?

I think you basically take the same approach, but you do it in intentional way. what Anthony said there is like, that's an accidental thing, right? You know, going along, doing our business, and then, oh no, this has happened. We have to do something.

We have to respond. If we just don't Turn the tables and approach the conversation in that way and say, have you got cyber insurance? It's cause they answered all the questions the way the insurance company wants to hear it, not the way Exactly, exactly. so if you then say, would you mind if I have a copy of that policy, let's have a look and see what your obligations are that you've signed up to, and then you depict that and realize they should be doing A, B, C, and D, and they're not.

Then you're able to force the issue, right? You can say, look, stop paying because they ain't going to pay out. You're actually just throwing that money away. You need to do these things.

And the same thing applies for contractual and legal obligations. So if the customer is involved in healthcare or they're in legal, understanding what the problems are in that industry, what they may already have agreed to, Same ideas as cyber insurance. What have you agreed to? What are you having to do, but actually find the real black and white writing?

Don't just say, oh, you're in healthcare. You're in legal, so you have to do this, this, and this, because they kind of already know that and they've already chosen to ignore it too. we're gonna get your hands on something solid and say, look, what could you've signed up to? We're not doing this for you.

We're not gonna be responsible for this if it goes wrong. we need to address this problem and go from there. help me out here. just came up with this one.

Nobody's ever thought of this before, I'm sure of it. Because all ideas I have are original. All let's say, yeah, so let's say I sit down with a company, and I say, do you have cyber insurance work? and if they say yes, it's pretty boilerplate at this point that cyber insurance is going to ask a number of questions like, do you have MFA enabled on all admin accounts?

so on and so forth, right? I'm sure you could even potentially Find that list somewhere of, What are some of the more common cyber insurance policy questions that the insurance company is going to ask to understand your cyber posture and risk? Because that's what insurance companies are doing. They're measuring risk to determine if your business is worth insuring.

When you sit down with that company and they say, yes, we've got cyber insurance, then start asking them about things like, do you use the little six digit codes? can you go to any website you want? So on and so forth. now you've got a baseline for what their cybersecurity actually looks like.

And then, unfortunately, this is a bit of fear mongering, but I think sometimes you got to tell people the hard truths and say, Hey, look, you are wasting your money because if you have a cyber incident, which based on your current cyber security posture, it's not an if, it's a when, You're going to try and make a claim, the insurance company is going to do an investigation and find that you don't have all of these things in place, that you maybe told them that you do have in place, and they're going to deny your claim.

I think that type of information is powerful because once you explain to a person that, hey, did you know you're wasting, thousands of dollars a year on this policy that's not going to help you, I think that, that starts to open eyes and ears for people. Yeah, it's a false economy, right? They don't, for some reason, I don't know why, but they're not sitting there thinking that they're throwing that money away. Because they don't ever believe it's not going to pay out, which I don't know why, because I've never met an insurance company that likes to pay out.

And I was talking to a claims manager of an insurance company a few days ago. He said to me, I've been in this industry 18 years. And he says, I can tell you, you're absolutely right. we all feel it.

But that's from somebody within, who's obviously confirming it. I think the customers often just don't think that's going to happen, because they've got it really messed up in their mind. They just think, oh, you know that, they've just forgotten. They've just, to them, the cyber insurance was just a stepping stone that they needed to get in place to win some contract, to win some work, and off they are now busy delivering that work with completely, Now, but now they've got the cost, but they're not thinking about, they're not associating the cost with claiming, they're associating the cost of that with doing business, which they had to do to win the work and push ahead.

So it's very powerful when you go back to the customer and explain to them, let's say they're spending 20, 000 a year on an insurance policy, which is not uncommon now, and say, look, you might as well set that money on fire in a car park because you're never going to see it, you're never going to see it back if you need to use it. one of the things that often sit and wonder about is how do we pitch different services to different industries or verticals? So, When you go and sit down with a law firm, you're going to have a different cybersecurity conversation than if you were to sit down with a construction company, how do you tailor your cybersecurity pitch to these different industries?

and I'm going to back up and assume that you're an MSP that, still is a generalist and you'll support all these different industries. You haven't specialized on a niche yet. some of the very topical actually, um, I've been dealing with in the last few weeks, both in my MSP and, and with HighGround and that is, so. And I'll share this.

Actually, no, I've not told anybody this, so this is a new, a new thing. Actually, we're here, and I mentioned on MSP Tutor, we've actually devised a strategy that I think anyone can use, and we call it, Packs and Tracks. if you've been selling products, or you're selling products with service. So, uh, Endpoint Protection, or Endpoint Protection with a SOC, and there's a service attached, and you're doing something, that's the hardest thing of all to sell, because the customer has no idea what it is, you might be selling things bundled together, like email and web protection.

Those things go really well together. They are kind of always, they always have done, right? You know, you have email protection and you have web protection because those are big sources of threats, or EDR and MDR, they go well together. IAM and PAM and password management, they go nicely together.

Now, in a technical team, They're sitting here trying to deliver all these different products and services and they have really no consideration or regard for what the sales team or account management are selling to customers but they get very upset when someone in sales sells the customer something they can't deliver and that becomes very frustrating and all these little nuances and anomalies between what one customer is supposed to get and what the other one gets. at the end of the day, It's always the same products that typically that we're selling to customers.

The only difference is how different customers need different products and services for particular needs. So you mentioned a couple of industries there. Construction is typically, certainly here in the UK, is typically focused around the public sector. Therefore, there's often a lot of compliance involved in that, aligning to frameworks and making sure that you are either, if there's something that's regulated, that, standardized that you meet that compliance requirement or there might be particularly niche standards and requirements you have to meet.

Whereas legal is an alternative example is we all, we all know largely that it's heavily focused in the feeders on data loss prevention, that we have lots of sensitive data and if that information is to get out into the public domain, we're toast, So we have to stop that from happening. Based on that, by creating these, what I call tracks, we're essentially taking the same products and service portfolio that we may have as an MSP and determining the ways in which we need to use them in order to deliver the outcomes the customer needs.

And they're largely, broadly, if you look at it from an industry perspective, pretty much the same. Financial services has a very heavy focus on detection because they're largely targeted. Data loss, legal was kind of the same. If also a strong focus on DLP, but you could largely put them both in the same place.

Encryption plays a big part as well. Encryption of data at rest and in transit. I guess to a certain extent, medical is the same in healthcare. whereas you go to some other organizations that are maybe a bit like the construction, deal with lots, much larger organizations.

They expect, therefore, because the governments and councils and places like that are running Like a government, they expect good compliance, good governance, good risk management, and we need to address those problems for them. as much as we can say they're kind of unique, they're really largely just turnkey solutions. Like you need to figure out what the flavor is of legal and just package them in a way that meets their needs. I like that.

Now, one of the things that I would like to think you've heard of by now, if, if you do any type of marketing for your MSP, there's something called social proof, and when you're building a website, you do social proof by putting testimonials and reviews, Case studies. so there's, all different ways to put social proof on your website, and maybe even on like printed material, like flyers, you maybe put on a little quote from a client who's using it, right? So, how do you implement social proof when you're, Trying to demonstrate the value of your cybersecurity services to clients and prospects.

That is probably one of the hardest things to do, because you could say, hey, look at customer A, Steve at Channel Programs never had a breach because he's bought our security package, but no MSP wants to say that, right, because they feel like you're, uh, touching wood when you say that. Well, no, it's going to happen now. If I say it, you don't want to jinx it. at the same time as, but those kind of are the security stories that.

We need to tell, because those are the good news stories. I think one thing we do need to do is need to try and steer clear of the bad news stories, because people often seem to, I don't know how, but they seem to be able to kind of remove that from their mind and forget that it ever happened, and they don't tend to have the impact that we think that they should. I think that, Focusing case studies and stories, customer testimonials, if you can get them, that really talk about the challenges that the customer was having and achieving their goals and how security was a part of that.

It could also be that fear of, you know, losing everything that the customer's built over all these years and not wanting to lose that and how much better they feel now. About, I've bought the security package and I can sleep a little bit better at night. I feel like I'm more involved and I understand my risks and my MSP works with me to make sure that I'm keeping on top of that and moving forward. Those are the stories that people that resonate with people because that's the gain that they want to achieve.

They want to feel like that same way. So you're kind of selling it on feeling but selling it on the positive feeling rather than the fear. If you sell it on fear, it really doesn't work. Now that makes perfect sense, yeah.

I think that whenever you're doing testimonials or case studies or anything, you should never include, well, it's okay to include some fear, like, I had no idea that I was so vulnerable, and I signed up with, Steve Taylor's computer whizbang and now everything's magically better, you know, like it's, it's okay for the, for the customer to, to be genuine and say, Hey, you know, I didn't realize I was, I was so open to, Bye for now. To attack and now I feel like I'm, much better and it's not that they couldn't sleep well at night before because they, they were, you know, blissfully ignorant before.

And, and I think, I think it's okay to have a conversation with a, with a customer and, Make them feel blissfully ignorant without making them feel stupid. I think there is a way to do both, when you get them to open their eyes and go, wow, like I get it now. that's when you have the breakthrough and that's when they say, who do I write the check to? You know what I mean?

Another way that you can accomplish this, besides social proof, is by sharing some key metrics or statistics. And that's hard because, you know, what do they say? 87 percent of all facts and statistics are made up, made that one up, right? So, uh, and lies, as they say.

I guess what I'm asking is, do you share any metrics or statistics to support your cybersecurity recommendations? And then how do you present those in a way that they seem factual and not like some crap you're just trying to say to get them to buy something? and the irony of this answer is I'm going to answer with a statistic, because, I read something fascinating a few weeks ago, all about storytelling, I'm actually personally sat, um, fascinated by storytelling and the impact that it has on people.

And, they use it a lot in marketing, right? the reality is I don't talk statistics. Our team don't talk statistics at all because customers forget them, the thing I read about statistics, Which is a statistic, is that apparently only 14 percent of people remember the statistics. But you see, if you tell in a story about Steve who ran Whizbang Computers, who had this problem, he was trying to win this contract with X organization who needed him to do this, and he didn't know what to do, and he couldn't afford it, and he was worried, and he spoke to us, and we worked with him, and we showed him this.

They say that over 60 percent of people remember a story. And if that story is relatable to them, it's even better. If they're that like, they're just like me, you know, I'm a Steve. I know how he felt because I'm there too, and my story is very similar.

So we tell stories about security, about people. That's why the case studies are powerful. because quite frankly, the statistics are either unbelievable or just not memorable. And they don't incite any action.

And what we want people to do is go on this journey. the thing is really important that you get your customers to understand going on a journey, that you're not selling them the destination. They're going on this journey with you. That's why they need someone they can trust, someone that they feel they can work with, and that you're going to be here in three months, six months, nine, two years, the same conversation, telling them what else they need to do now, because it's not just going to be over.

And the statistics are going to change, but, whatever they happen to be, they're still going to have to deal with them. So can I, and the thing about storytelling is you've got to make the customer, the main character and the hero in that story. So you want them to feel like they're succeeding, that they're winning, that they are achieving their goals and you need to go to take yourself out of it as the MSP. You don't matter.

You're just a facilitator to help them get there. That's when the customers really get, really get engaged. if you were to get, A client to do just one cybersecurity change. and you had to pick just one service to get them on board with what is it and why is it, cybersecurity awareness training?

Security, we're in a straight end. Yeah. do you think that's probably like, if, if you sat down with a company and they don't have MFA, They don't have DNS filtering, and you know, they, they click on freaking everything. where do you start?

What's the first thing you do? Is it training them, or is it, I'm gonna implement a baseline of changes that, implementing some of these changes is going to drastically affect how they do things on a day to day basis, whereas the training, I always feel like educating people is less friction than I'm going to make you all type in six digit codes and I'm going to make it so you can't access all your websites and so on and so forth, right? and you know, on that point about awareness training, I think that, and we do see organizations, we all see organizations like that, right?

I, I'm a believer in getting their work in front of them, but you roll out a program of security awareness training and just think that people are going to adopt this, if the problem is that bad. You really want to be getting them collectively in a room together or even identifying the individuals and speaking to them and really helping them understand and then enroll them in training rather than simply Here you go. Do some training because they think oh, I already know this.

I've seen this, you know, you can't teach me I understand. They can even get through the test, but then you go and do something stupid anyway Make them understand and realize that the risk that they pose to the business and the impact that could have and that they need to sometimes slow down and think. as for the technology that I would implement, for a single technology an organization's systems, I think, I mean, MFA would obviously have to be one of those things, but I really think that we're leaning now much more into, IAM solutions, so Identity and Access Management, and extending that out with SSO to as many places as possible, because then we're really trying to reduce the number of times the customer's likely to be doing that, So we're trying to leapfrog the current problem and get them to a place where they're using these credentials less and less and if you turn on MFA on to that, then you can have a significant impact on likelihood of the things that are happening.

So basically trying to problem rather than treating the symptoms, That makes perfect sense. now let's talk about something a little more complex. I'm going to simplify the complex as best as I can. Let's say you sit down with a dentist and you're here in the States.

So that means patient data, right? presently, They don't know if they're compliant with HIPAA guidelines. they don't know all the things they should be doing. They don't necessarily care.

How do I have a conversation with them to either get them on board or figure out if I need to run? because we don't want to stick around if they're not going to be compliant because that puts us, the MSP, at risk, right? if we're going to talk to our clients about risk, we got to talk to ourselves about risk, too. if you take on a client that.

is supposed to be compliant, and they're not, and they don't give a darn, then do you really want that client? Because now you're opening yourself up to risk, and maybe your own claims won't be approved in the future. this is a good question because I think it's actually the answer to it kind of depends on the size you are as an MSP. You know, the smaller ones are much hungrier for work and they're much more likely to take on the risk and believe the customer is going to make the change.

Whereas the larger ones, particularly the ones that are now getting involved in like M& A and now getting bought up. then, much larger organizations are thinking, oh, do we want that risk? And so they're much more likely to just shun it and turn it away. if the middle ground is somewhere in between those two extremes, then, I think you really need to sit down with, during that sales process.

If you have not addressed it in the sales process, which you really should have, then you definitely need to address it at the onboarding phase with the customer to understand, document, Do you understand your obligations? What are your intentions? And put that down onto a risk register. You know, develop a risk register with your client on that same risk register as the old 2008 or 2012 server that needs to be replaced and what that means and the Windows 7 computers that are still kicking around and any operational technology might take the business down.

But document that and have the customer recognize that This is a risk and you need to do something about it and put a date on that. So when you get to that next QBR, if you really, really want to take on that business, but you're just not sure they're going to do it, and you don't want to get caught up in this for a long time, make sure that you address that risk register at the first QBR. That's going to be your first warning sign. If you're getting two, three QBRs down the road and things are not changing, Then you've got, you've got an out.

And not only that, you've documented it at the start. So if someone comes knocking and says, hang on, you were involved in this, you say, look, we documented that. They knew. We told them, we advised them, and they didn't want to do anything about it.

Then it does give you some, I guess some comfort in knowing that you've addressed it. the last question I want to ask you is about budget. So when you sit down, whether it's a client or a prospect, you need to understand the budget. How they budget for IT, here's where it starts to get a little nuanced.

because some companies do their accounting differently, but, if they're running a halfway successful company, they should have a budget for the year, and they should be planning their budget for the following year. So, how do you have that conversation with them and say, hey, look, I need to know what your IT budget is, so that way I can help you prioritize, different expenses and upgrades and purchases based on your budget, because the budget can't just be, I'm paying 4, 000 a month to my MSP.

There, there should be a larger budget than that 48, 000 a year. because projects and upgrades also need to happen, So get that question answered tactfully as early as possible so that way you can help them be successful? if it's the first year you're working with a customer, that should be the only year you ask that question. because you're, In a cycle now, but what you really should be doing is sitting down with the customer saying Steve We need to work on your budget for next year.

That's what vCIO tools are trying to do, right? It's like we've got all this stuff needs to be done and we've documented these risks and we know these projects and we know that you Can't just put a hundred thousand two hundred thousand into it So we need to Make priority based decisions, and you need to be involved in that, because you need to understand what risks you're taking. And they're not just security risks, could be operational risks as well. Compliance and regulatory risks like we've talked about already.

And from there, help them build a budget that's going to achieve it. So if they say, look, sorry Steve, but the budget's 60, 000, there's nothing more I can do this year. You say, okay, well what are we going to do? And we're going to address those.

And work on them on a 2, year plan to start addressing those things. If you try to make their problems fit into their budget, you're in for a hard time because it's never going to fit. follow up budget question. How do you explain to them their IT budget needs to increase every year?

Do you say, hey, we need to, we need to build in a 10 percent annual increase or what's your strategy for that? Yeah, I mean, you need, I think you definitely need to make sure that it's tracking inflation. I guess there's never been a, there's never been a more realistic to be having that conversation right, right now. so addressing that for sure.

But I think it has to also be on, on like, what do they want to achieve? How does that align to business goals and the risks that are there and build it towards that rather than, and then on top of that, also add in the inflationary aspect of, look, everything's going to cost more next year than it costs this year. That's just a fact of life addressing it in that way and being open and honest and upfront with them. I think most people, I think we're all quite lucky right now.

It's been hard living through this time of inflation, but it's also people are a lot more aware of it where they weren't before. But people have seen eye watering inflation over the last two years. So they're a lot more open to it. And now would probably be a great time to broach that subject with them again and just make sure they're on, that they're understanding.

Wonderful. Mark, thank you so much for coming on here and doing this with me, man. I really appreciate it. if you guys are interested in.

Connecting with Mark, look him up on LinkedIn, Mark Lamb, just like the animal, L A M B, check out his company, High Ground, you can go to High Ground, uh, H I G H, ground. io, is that right? That's right. Yep.

High Yeah, check that out, and what does High Ground do for MSPs real quickly? ground helps better security conversations with your clients to sell more them reduce your Wow, how fitting! Thanks, everyone, for listening. And we'll catch you next week at the next MSPTutor.

Take care.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Aaron McCray: Ferrari Security: Speed With GuardrailsKitecast · on Multi-factor authentication (MFA)88 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100
  • Breaking Through With Analysts - How to Win Gartner’s Attention - Dan Lowden CMO BLACKBIRD AICyber Go-To-Market Talk · on SentinelOne78 / 100
  • Ep. 5: Food and Agriculture featuring Jonathan Braley, director of the Food and Ag-ISACThe Security Detail · on Multi-factor authentication (MFA)78 / 100
  • Ep 114: Top 5 Cybersecurity Best Practices with James BierlyLevelUp Cyber · on Multi-factor authentication (MFA)77 / 100
  • Navigating Cryptocurrency Security: Sim Swaps, Vendor Risks and Assertive MeasuresEncrypted Ambition: Where Ambition Meets Encryption · on Multi-factor authentication (MFA)77 / 100

More from the RocketMSP Podcast

All episodes →
  • From Rejected to Respected: How to Create Your First Conference Talk | MSP Speaking Tips63 / 100
  • From Break-Fix to MSP Evolution: Brian Weiss on Surviving Security Incidents, Building Culture, and the Future of AI in IT80 / 100
  • An Interview with Fred Voccola, CEO of Kaseya84 / 100
  • MSP Security Simplified: How to Automate Endpoint Hardening | Zach Kromkowski from Senteon
  • One MSP's Cybersecurity Maturity Model with Josh Hohbein from CentrexIT
Explore the best B2B Ops podcasts →
All the RocketMSP Podcast episodes →