Archives For Data Security

Move from MSP to MSSP and you’ll immediately realize 3 benefits (that just might save you from impending doom).

Advertisements
Continue Reading...

Solution Strategy 2.0

Download the Roadmap Here: https://davidstelzl.net/freeroadmap

Copyright 2018, David Stelzl

 

What to ask when conducting your security risk assessment

Continue Reading...

How to answer sales objections when selling MSP solutions using risk assessments [free assessment template]

Continue Reading...

businessman hand working with new modern computer and business s

It’s Easy to Leave A Channels Event, Distributor Conference, or Mastermind Group feeling good about your MSP business. After all, your business is producing a profit.

You’ve been in business for 20 years or more. And you’ve managed to weather several economic downturns over the past couple of decades.

Don’t get too comfortable…

The high-tech business is a fickle thing…there are economic downturns (recessions, depressions, or whatever you want to call them…) and then there’s commoditization. The latter is your greater enemy.

Like medical and grocery sales, people need their computer. The high-tech business (servers, storage, data center, etc.) has been a high growth industry since I entered the business world out of college. It just has…perhaps it always will…tech is the lifeblood of most businesses today.  We can’t work without it.

However, It commoditizes.

Building Sustainability Into Your Business

This week I’m attending a marketing conference in Cleveland OH. Over 1200 small business owners packed into an auditorium listening to some of the greatest entrepreneurial minds in world.

This morning’s session focused on sustainability.

As the speaker unfolded over an hour’s worth of strategies, the MSP business  came to mind…a business that relies on long term customer retention.

MSP sales are not transactional. In fact, if your clients only stayed a month or two, your cost of sales would eat your business alive. You really need them to stay.

Historically, retention in the MSP business is 5 years (average). Yours might be more or less, but you should know your number. The goal is to increase it. If you could add just one year to your average (assume you have 100 clients signed on), that’s 1200 months of MRR (Monthly Recurring Revenue) added to your business in that one single act. Or think of it as signing a 1200 year contract with your next client!

5 Things You Should Be Doing To Create Sustainable MSP Business…

Build Evergreen Assets.  If you’re taking care of your customer, you’re probably meeting quarterly to review their IT. Hopefully you’re also giving them guidance. During the initial sale you also had to review their business and create some sort of proposal.

However, building everything from scratch is destined to fail. The cost of customization is high, and the likelihood of messing up is high too…Better to productize your offerings…here’s how.

First, you should be selling packaged offerings. There’s your core MSP offering, and then there are add-ons (like riders on an insurance policy).  However, when you buy a car, those extras are often bundled into packages. The electronics package with the stereo upgrades. By doing this the dealer eliminates the headache of creating a completing customized quote.

In this case you need at least one (but probably more) security package…one that can be added to their existing MSP agreement (if someone else holds that contract), or attached to yours (now or later).

There’s also a maturity model…if you were to create a maturity roadmap for security, when your new customer joined your program, you would figure out where they are right now, and begin taking them through your 24 step program…certain mail pieces, meetings, assessments, and sales efforts would be made along the way – all predetermined.

Building Identity. Customer loyalty is also a key to sustainability. Not everyone will be loyal, but the hotel and airline industries, as well as Amazon and Starbucks, have all proven that people will join the club if you sell it the right way.

It turns out identity (the people group, brand, or team I identify with) will drive my behavior faster than just about anything else. I’m a lifetime platinum member of Marriott…when it’s time for coffee, I’m waiting in line at Starbucks in the airport, even though there’s a coffee shop right across the hall with no wait. Why?

I’m part of the club. I identify myself as a Starbucks customer, I stay at Marriott unless there just isn’t one…and I’m not the only one.  If you’re sitting there telling yourself you don’t do that, remember, you’re not you’re own customer…you want to sell to people who will sign on with a brand and stay.

Sell to The Right People. There is a people group out there worth your time…but there are also people not worth selling to.

Your job is to identify the people group you work well with, and go after them. I was talking to a very successful entrepreneur this week – he told me he sells to men, age 45 – 60, ambitious, hard working, leaners, who are already in business. He also noted it’s best if they are married, politically conservative, etc. You might think he’s too narrow. Yet he’s made millions (plural) of dollars in personal income annually over the past decade.

Signing the wrong people onto a business that demands retention is a recipe for failure.

When identifying your perfect customer (the customer avatar) you’ll want to know how they think…the more you know what’s on their mind, the better.

Today’s speaker said it like this…”Know what they are thinking about every day as they leave the office…know what they talk about around the dinner table each evening…and if they wake up at night worrying about stuff, you should know it.”

In the End They Need Hope. Dave Ramsey does one of the best jobs of selling hope.  He tells his team, when you pack up a book or CD to ship out, it’s not a book, it’s a package of hope.

With MSP; remember, most small businesses are frustrated with computers. They don’t understand them, they don’t really trust them, and when it comes to security, they’ll do just about anything to avoid thinking about it.  Security issues just create more stress…

Want To Build The Sustainable MSP Business?

Stop trying to copy the models presented by MSP cloud offerings around you. They don’t know how to sell to the SMB market. They know how to sell to you…I’m talking about the SolarWinds, Continuums, and nAbles of the world…

Be radical…start thinking about what a small business really needs…what would remove all the IT stress from their world.  And then start providing it to your ideal customer avatar.  Add one year to your average, and then continue to journey. It’s the road to MRR growth…And it’s sustainable.

© 2017, David Stelzl

P.S. Do you have my Security Assessment Report Template…Designed to move prospects into your program quickly?

Businessman sinking in heap of documentsHere’s What Business Leaders Are Saying They Want in An Assessment Report (in Two Words).

“Security Intelligence”…

Will the CISO actually read your security assessment report? What about the small business owner? Law firm partner? Doctor running a clinic (where HIPAA is required)?

The likelihood of anyone reading your report is nearly ZERO!, unless you do this one thing first…

Separate the Technical from the Business Risk,…

That’s right, you need two reports. One written in the language of leaders, the other technical. But don’t just create a new report just yet…here’s a simple process that creates ONE REPORT, with two parts, giving your report better flow, while at the same time appealing to both audiences.

(Download my Free Assessment Report Template – We’re converting over 73% into MSP/MSSP contracts)

Executive Reports Should Not Have Stop Lights In Them

Let’s start with the executive summary. First, drop the word summary…and delete that one page summary page in your report. Call it the Executive RISK ANALYSIS…with an appropriate subtitle.

I’m 99% confident your current one-page summary will not speak to executives…and if it has the RED STOP LIGHT on it…well, check out what one CISO said in a recent interview…

Tom Watson, CISO for Sealed Air Corp, told me just a couple of weeks ago, “The stop light approach is meaningless”.

Having a red light on the summary page does not lead to immediate action or follow-on business for the consultant. There is no business justification in a red light. PERIOD.

The CISO’s job, according to Watson is, “To bridge the gap between technical and the board.” “My seat at the table,” says Watson, “Is where risk gets delivered in business terms to board members and my C-Level Peers.”  In other words, the stoplight diagram does not quantify risk…the board won’t be moved by blinking lights.

Red Lights On Risk Reports = Idiot Lights On Your Dash

If you have an older car, the red light comes on when something is wrong… that could mean your gas cap is off, your catalytic converter malfunctioning (and you might not pass your next emissions test), or your entire transmission system is about to fall off while driving down I-95 and 70 mph.

In other words, anything from a simple 2-second turn of the gas cap, to the $3500 transmission replacement project will satisfy the red light. But which is it? No one seems to know. So the new cars tell you what’s wrong (in one of N languages).

Your executive risk report is the same. The light justifies nothing…instead, you need an explanation…(in one of two languages).

So what will you explanation look like?  A quantification of risk…a measure of Impact vs. Likelihood…Language ONE is BUSINESS…Consider the following…

  1. What assets were identified as having an associated risk? And what are the relevant threats, posing risk, which must be addressed?  Are you aware many companies don’t even know where their data is? And so figuring out where the assets are, what threats exist, and how big those threats are can bring tremendous value to your C-Level contact before meeting the board.
  2. What are the odds data will be affected? Going back to the three pillars of security: Confidentiality, Integrity, Availability…it makes sense to find out which of the three matter for any given digital asset, and to quantify the risk (as a percent likelihood) in a graph.
  3. Finally, what is the trend? Is business risk increasing? Or is the firm’s security posture improving over time? As the company adopts next-gen technologies, leadership need someone watching risk levels. As IoT projects, mobility, collaboration, etc. evolve, are business threats growing, remaining constant, or shrinking?

The report should be short, graphical, and written in business-eze. I highly recommend having someone with business-savvy right this report. But don’t stop there… have a copywriter review and edit it.

Copywriters will take a boring report and turn it into engaging content. They’ll trim it down, bring out the headlines, and bring it to life, keeping your overworked reader engaged.

With one solid report in hand, it won’t be difficult to duplicate. If you look at the popular business books on the NY Best Seller List, you’ll see they have a readable style unlike any college text book or legal document. It’s that level of readability you are looking for in your report.

NOTE: This means, when you use vendor-reports coming from SIEM, firewalls, etc. The reports they give you (while colorful and complete) will not land new business…Keep reading to see where your colorful-vendor report goes…

The Technical Stuff (Including the Vendor-Report) Belongs in Appendix A

While you might be tempted to combine your executive report with the details, handing in the 100 page (War and Peace) report is not going to bode well for you. No one in the C-Suite has time to read 100 pages!

Business owners are even less likely to read a report that looks like a 5 hour project.

At least a CIO or CISO is responsible for risk as a primary job function. The small business owner, while responsible for computer security, is more likely to be focused on today’s invoices, a major customer-sat issue, or this month’s cash flow crisis.  The 100 page report is likely going on a shelf…or in the round file.

If you create two reports, another problem emerges…the executive has one report, technical has another…are they different? Do they conflict?

The Solution is Easy…Appendix A!

Most of us skip the appendix when reading a book.  But knowing the data is there gives us assurance that there’s research behind the author’s claims. The technical team will have access to the main report, but will likely find the details in you appendix more interesting.

Here’s What You Should Include (Notice there’s no stop light here either):

  • Network diagrams
  • Applications / Digital Assets (Prioritized)
  • MTD/RPO requirements (Data they don’t have up to this point)
  • Any important business level requirements
  • Technical details on malware, configuration problems, etc.
  • Gap analysis against whatever standards you measure against – XTZ compliance, NIST, etc. (I highly recommend you base your assessment on something such as NIST to give your findings more credibility)
  • Major issues to address (project recommendations – keep this list short)
  • The punch list of everything else that should be addressed.  Prioritize this list, and segment by functional area.

Between these two reports, you have what you need – however, the move to remediation has more to do with your presentation than it does in these two documents.  Look for a future article on,…

“How to Master The Board Room Presentation, When Presenting Risk Findings…”

© 2017, David Stelzl

How Long Will Your Business Remain Relevant…

…As Companies Around You Are Transitioning to Cloud, Consolidating IT, and Buying Less Hardware???

This morning, in my TechSelect Business Pillars Session, I delivered urgent steps of action EVERY technology reseller should be jumping on…here’s a summary:

Over the past 12 months, live event, one-to-many selling, has produced more leads and deals than just about anything.

The value of one MSP client in the SMB market averages at about $1500/month, or $18,000 per year – with a 5 year average retention rate, that’s just short of $100,000 per client!

Add advanced security to that deal and you’re likely to push your average up 20%…(Mid market deals, although harder to close, offer even greater potential if you understand the sales process I describe here).

What would your business look like if you could hit the numbers I reference in this video? What would it be worth to you to achieve this level of sales?

Find out in this 25 minute video how to re-engineer your business, with a new breed of security, now becoming a necessity in the SMB and mid-market space.

© 2017, David Stelzl

P.S. Get the step by step process in written form – The House & The Cloud