Every day I have conversations with MSPs that offer insights into their customers’ reservations regarding investing in security. I often hear, “My customers don’t see the critical importance of security,” or “My customers don’t believe they have anything cybercriminals might want.” But here’s an interesting fact: Your customers possess something of great value to these cyber criminals — money.
Every customer has something valuable, making them a potential target. Therefore, a certain level of risk is associated with not mitigating that risk. The question then is, what might that risk cost your customers if they were to underestimate it and fall prey to it? That’s a pivotal conversation you’re empowered to initiate with them.
Your customers operate in a world where technology is essential. They rely heavily on technology to drive their businesses forward. Imagine their routine without internet access, customer relationship management (CRM) software, or essential accounting and management software for even a single day, let alone a week or two. Can you visualize the impact on their revenue? How would they navigate through a scenario where cybercriminals held their data ransom?
When a customer finds it challenging to see the value of investing in security, we can reevaluate our approach. But here’s some friendly advice: The challenge lies more with us, not the customer. Consider the monthly increase from $3,500 to $4,500 — it might seem substantial from our perspective, but it’s a reasonable assurance for your customer’s security in the grand scheme of things. That’s the value proposition we may not be communicating effectively.
As we look forward, there are immense changes and opportunities in the MSP industry. The moment has arrived for us as MSPs to place security at the forefront and guide our customers in making better investment decisions.
When a new technology emerges, we often naturally draw comparisons to familiar concepts. A prime example is the recent debut of Apple’s Vision Pro, which has ignited parallels with the decade-old Google Glass. While the majority are discussing the technical similarities and differences between the two, a compelling conversation around the concept of opportunity cost has caught my attention.
An interesting question was presented in a recent article: What if you had chosen to invest $1,000 in Google’s stock instead of shelling out it on Google Glass in 2012?
Let’s dive into the numbers. According to the article, your $1,000 would have netted you about 1.66 shares of Google stock in 2012. After factoring in stock splits over the years, you’d own 66 shares today. As of last week, these would be valued at $128 per share or $8,500.
This raises the question: Did your purchase of Google Glass really set you back $1,000, or was it a costlier $8,500 in missed opportunity?
Accruing after-tax dollars in your personal bank account is among life’s more challenging tasks. Therefore, grasping the true value of those hard-earned dollars is a cornerstone of financial success. Business leaders should prioritize establishing profit goals ahead of revenue targets. In personal finances, shift your focus from income to net worth goals. Such a change in perspective could prove invaluable in making informed decisions over time, prompting you to reconsider how and where to invest after-tax dollars.
Remember: The actual cost of depreciating items extends beyond the purchase price — it includes the opportunity cost as well.
One of the most important metrics for a managed service provider (MSP) is the average monthly recurring revenue (MRR). It impacts scalability, profitability, sales, math and customer acquisition cost (CAC). It also has a significant impact on the value of your business. So, there’s one thing everyone can do immediately to impact the average MRR — set a minimum MRR amount.
A minimum MRR is a minimum dollar amount under which you would not bill a customer, so rather than defining your customer by the number of seats in terms of a minimum, determine it by a minimum MRR. How you set this and what you should set it at is relative to your starting point. Over time, everyone should have the goal of having a minimum MRR that is above $3,000 per month — that’s the bare minimum.
You may not be able to start there based on your situation but start somewhere. As your business matures, move up your minimum. Next, when you set the minimum, look at your customer base and see how many customers fall below the minimum. If you’re setting the amount correctly, a third or so of your customers will fall below that line. Then make a plan to fix or replace those customers over time.
Service providers often struggle financially, even when their business is growing, because it can be challenging to achieve and maintain profitability. MSPs have seen success by adding security services to their offering to offset this challenge. However, security needs vary across customer accounts and some can be more complex than others. Ultimately, this can further perpetuate the challenge to control profitability.
For example, smaller customers who are taking advantage of a co-managed account relationship with an MSP can generate service costs above the standard subscription fee. Because they don’t have the same internal resources as their larger counterparts to handle level-one support or security issues, this places strain on the MSP’s resources.
Another reason why an MSP might find it hard to maintain profitability while delivering security services is that customers may generate unnecessary alerts or consistently reach out for levels of support they aren’t subscribed to, again draining the MSPs resources, without adding revenue.
To alleviate these challenges, it’s vital that MSPs take time to consider whether there’s a way to make each customer more profitable. This could mean charging more for security service support or leveling late payment charges, for example. Even if those efforts result in lost business, you may be better off dropping an unprofitable account if it gives you more time to drive business with more profitable customers.
Other strategies that can help MSPs make their services business more profitable include:
Thoroughly analyze each account and continuously measure profitability via quarterly benchmarking. This will help to quickly identify the problem accounts and point to some solutions (like pricing or service utilization) that could be adjusted to shift that account from the red to the black. This will also give you a better view of your performance against your goals over time. In some cases, you may cut loose accounts when appropriate. This can affect total revenues in the short term, but will help boost the average margin.
Ensure clients are using the systems and services they are paying for. If customers don’t use every module on their plan, the unused items still create overhead for the MSP. Offer a usage analysis, which can allow the customer to drop services they do not need. That may reduce the amount they pay the MSP, but minimizing the resources required to support them could make them more profitable.
Make sure you’re not underpricing security services. While many clients are very cost-sensitive, service charges must cover your costs and provide a sustainable margin. Security provides a strong value proposition, particularly with attacks on the rise. Your offerings should be priced to reflect that. MSP’s can avoid discounting by pointing to the costs associated with not protecting your business. In the long run, the monetary costs and impact on the customer’s reputation can be far more than the cost of protecting the business in the first place.
Account for inflation. Costs have risen sharply over the past several years thanks to the pandemic, global instability, and supply chain issues. In the current economic environment, the actual service costs (including your rising overhead) need to be recalculated and reflected in pricing. Your clients are doing this right now, as well.
Implement technology that reduces your internal costs and labor. For example, a remote monitoring and management (RMM) tool that can deliver security services through a single dashboard, allows you to monitor multiple client networks with fewer resources, reduce multiple security management requirements, and can help streamline training for new technicians. Automated alerts and first-line response tools can also make staying on top of potential threats easier to do without hiring more staff or over-extending existing teams. Partnering with vendors that have designed their technology for an MSP environment is also beneficial.
Leverage your vendor partners to outsource complex tasks. Partner with a vendor that can provide services that are resource intensive, such as a 24/7 security operations center (SOC). This can help to increase your effectiveness regarding security reliability without hiring more hard-to-find technical staff and other resources.
All of this will require MSPs to clearly understand what it costs them to provide security services. With threat levels constantly evolving, many firms are learning that paying a premium for reliable security services is worth the cost. As a result, MSPs should invest in technologies that allow them to streamline and centralize their internal operations as much as possible, while simultaneously pricing their offerings based on the value they provide. Your clients should not treat security like a low-value commodity – resourceful MSPs can use this to their advantage when it comes to pricing for profitability.
Neal Bradbury is Senior Vice President, MSP Business for Barracuda, a trusted partner and leading provider of cloud-first security solutions for managed services providers. In this role, he is responsible for driving business value for the company’s MSP partner community and alliance partners.
At Schnizzfest this year, I spoke about the downfall of the once prosperous ice industry — a significant enterprise that failed to adapt in time and consequently vanished.
A similar fate has befallen giants like Nortel, Blockbuster and others that failed to read the tea leaves. This week, an article in the Wall Street Journal caught my attention. It discussed Intel, the once-dominant force in chip manufacturing. Due to their complacency, they allowed Nvidia to carve out a niche in graphics chips. Fast forward to the present, and Nvidia is the leading force in artificial intelligence (AI) processing.
Intel has invested billions in manufacturing facilities to function as a contract manufacturer for others but has yet to see the expected demand. Meanwhile, Nvidia has significantly surpassed Intel’s market cap.
So, what’s the takeaway?
Our market is changing. The needs of our customers are changing. Our roles within the industry are changing. We must stay aware of these shifts and avoid default responses like, “Because that’s how we’ve always done it.”
As an industry, we must embrace incremental adjustments to roles, tools, processes and pricing as we look for more significant changes on the horizon.
Make compliance risks stakeholder friendly with myITprocess!
If you are an MSP, your primary responsibility is to keep your clients’ IT environments secure. Proactively identifying compliance risks is one crucial way to achieve this. However, this is only half the battle. Getting your stakeholders’ buy-in could be even more challenging since they might not know how the compliance risks impact their day-to-day operations and overall business.
Getting your clients on board by explaining how you plan on tackling compliance risks is no small feat. Our new integration with Compliance Manage GRC could be the solution you’re looking for.
With this new integration, you can add the compliance risks automatically discovered by Compliance Manager GRC into an IT roadmap in myITprocess to get stakeholders’ buy-in on the timeline and budget.
Turn compliance risks into accepted projects
Risks identified by Compliance Manager GRC will automatically surface in myITprocess, so no compliance risks are left behind. Moreover, you can have all your technology and compliance risks together in one view.
Here is a list of these risks you can view in a unified view:
VulScan issues — Network vulnerabilities
Technical issues — Password weaknesses, anti-spyware not installed
Requirement issues — HIPAA, network operations and monitoring, threat identification
You can easily add the risks that surfaced from Compliance Manager GRC into a myITprocess roadmap to get stakeholders’ buy-in on the proposed timeline and budget on all compliance issues. You can present the IT roadmap in an interactive, easy-to-consume presentation to easily capture their decisions and hold the clients accountable. You can also automatically summarize decisions made during QBRs on compliance risks in an automated post-meeting report and easily reference this to see progress.
Complete visibility of risks with myITprocess standards library
By supplementing compliance assessments with other standards in myITprocess, you can automatically bring the risks found in Compliance Manager GRC and have a holistic IT discussion with your stakeholders by utilizing the out-of-the-box myITprocess standards library.
This will help you access the following areas:
Hardware issues
Software updates/upgrades
Server infrastructure
Licensing information
Environmental concerns
Fire suppression
Air conditioning
Data backup
Core infrastructure
During QBRs, you can holistically present all identified risks that are tied to stakeholders’ strategic business initiatives to get their buy-in.
Visit our Knowledge Base for more details and step-by-step instructions on how to set up the Compliance Manager GRC integration.
MSPs have varied opinions on the impact of hybrid work environments on productivity and culture. While many MSPs have embraced the way of working in the new world and adapted their cultures to it, others continue to struggle.
There are a few things I’ve picked up from speaking with successful MSPs working in hybrid work environments. First, they’re very deliberate in their communications and with meeting rhythms at every level. Missing a weekly one-on-one with a team member is no longer an option for a manager or leader. Unlike when managers and leaders were in the office, skipping a meeting with an employee is now considered a huge deal and can negatively impact an MSP’s workplace culture.
These MSPs also have more accountability and visibility into metrics for each role. Every team member understands the tasks and metrics for which their role is accountable, and there needs to be reporting in place.
Additionally, there’s another consideration — the customer relationship and how having many customers in a hybrid environment affects the relationship with the customer. Face-to-face communication is powerful; it’s critical to relationships and meaningful to us as humans. MSPs are working harder today than ever to have face-to-face time with customers. Are you facing the same challenge? If so, have you made changes to your delivery to consider this with your customer relationships?
In your team and customer relationships, ensure you are adapting to the world around you.
When assessing managed service providers (MSPs), you frequently hear the term “operational maturity” in our industry. In other words, how mature an MSP’s operations are. However, when I evaluate an MSP, I first look at its “customer base maturity.”
Here’s what you have to remember: All revenue dollars are not created equally.
Each quarter, you should be reviewing your customer base. Drawing near-fit customers behind you as you grow is why you’re not growing as quickly as you’d like. I’ve always looked closely at this, but I have a different view today than a few years ago because, in the past, the only tool we had in our holster to fix it was to sell to new customers at the right price and then replace them at the bottom. Today, we have a lot of tools that can impact the quality of our customer base.
So, what does quality mean? It means the average MRR and the percentage of customers above your minimum target, your all-in seat price, customer concentration, reactive tickets per seat, how much they utilize your stack and more.
You can categorize your customers and, each quarter, try to make some progress. This means getting all your customers on your latest offering price, adding new services and proposing projects that help with alignment.
The truth is this: Your customer base says more about your MSP than any other indicator.
So, what does your customer base say about your business?
At Schnizzfest earlier in the year, I spoke about self-awareness, how difficult it is for us to be self-aware and how much it impacts our lives. We all see this play out in our relationships, and I see it from TruMethods members regarding what holds them back from fulfilling their true potential.
You can lead a happy and fulfilling life without maximizing your capabilities. The issue is when you want or need your business or career to be different. In other words, you’re capable but not seeing results.
A thing stands between you and what you can accomplish — and I call it “the haze.” Essentially, you’re trying to see yourself, your role or your business performing differently, but the route to get there is viewed through a haze created by your self-image.
We, as human beings, find comfort in the haze. It makes our world smaller and safer and allows us to continue seeing the world the way we want. For example, when we’re in the haze, we don’t have to try new things that may fail. We also avoid having that hard conversation with a long-term employee that the business may have outgrown. We create this haze to keep ourselves safe — but it mainly prevents us from growing.
One of the main reasons why we have peer groups is to help one another see through the haze. The most rewarding thing for me is to see the haze lift and watch people begin to feel the thrill of fulfilling their potential and helping others do the same.
The moral of this story is that when someone tells you something or challenges you on a decision or a closely held belief, don’t dismiss it as “I know better.”
Consider everything. Ask yourself, “Is this my haze?”
Perfectionism can be the enemy of good. While tempting, it’s an unattainable ideal that can lead to disappointment and frustration, hinder progress and prevent experimentation. It demands flawless execution without room for error or deviation from expectations. However, there’s another way to look at things — by accepting that imperfection is a natural part of any process, you can achieve greater adaptability, resilience and growth in your business.
Too often, people try to figure something out completely before taking action — but you can’t figure out most things on a whiteboard or spreadsheet. Instead, it’s best to have a framework for what you want to accomplish and ask, “What is the minimum amount of resources we can employ to implement something so that we can get real-world feedback?” In other words, don’t shoot an ant with an elephant gun.
The most straightforward answer is always the best one. Avoid over-engineering solutions and processes with more planning. (Ever heard of paralysis by analysis?) Your first version of something is almost good enough, so go with it.
The MSP business is changing quickly. We’re rolling out new services, using different go-to-market strategies, and changing how we deliver value daily to our customers. This means that processes, teams and reporting are also evolving. We can only keep up by simplifying how we do business.
Some ways to do that include:
Looking at your quarterly action plan and asking yourself, “Is there a simpler way or route to action?”
Asking your team leads to simplify the processes in your delivery areas.
Standardizing workflows to ensure consistency.
Simplicity is the key to unlocking greater productivity, creativity and success in the MSP business landscape. By embracing simplicity and avoiding the dangers of perfectionism, teams can increase clarity, reduce friction and communicate more effectively toward shared goals.