MSP Cybersecurity Sales Playbook

MSP Cybersecurity Sales Playbook title card with a shield icon in the MSP Pentesting brand style.
MSP Pentesting logo darkmsp pentesting logo dark

An MSP cybersecurity sales playbook works when it stops being a pitch and starts being a calendar. Your clients don't buy security because you explained the risk well. They buy when something forces the question. A renewal. A questionnaire. An audit date. A peer down the road who got hit. The playbook is knowing which of those is coming and what small, priced, finishable thing you put in front of them that week. MSP Pentesting is channel-only white-label pentesting for MSPs, MSSPs, GRC firms and vCISOs, so we sit behind these conversations instead of in front of them. Your brand on the report, our testers doing the work.

Most MSPs run this backwards. They build a security stack, price it as a new tier, and then wonder why nobody upgrades.

Nobody upgrades because there's no reason to do it this quarter instead of next.

Sell into the book you already have

You already own the hardest part. Trust and a standing meeting. A new logo costs you months of chasing. An existing client costs you ten honest minutes at the next QBR.

Pull your client list. Four columns.

  • Insurance renewal month, if you know it. Ask if you don't.
  • Regulated or contractually bound: HIPAA, PCI DSS, CMMC, SOC 2, state privacy law.
  • Who actually signs. An owner, a CFO, a board, or a parent company.
  • Last time anyone independent looked at their environment. Usually never.

That last column is your pipeline. It's usually most of the list.

The trigger events that actually create budget

Demand doesn't show up because you sent a newsletter. It shows up when somebody outside the relationship asks a question your client can't answer. These repeat.

Cyber insurance renewals

This is the best trigger you've got, and it runs on a schedule you can predict. Applications ask whether MFA covers remote access and privileged accounts, whether backups are tested and kept separate, whether EDR is everywhere, whether an incident response plan exists. Your client signs that application. You're the one who actually knows the answers.

The conversation opens itself. "Your renewal is in March. Last year you attested to a handful of controls. Do you want me to verify those are still true before you sign, or would you rather find out during a claim?"

That isn't fear selling. That's a signature they're already on the hook for.

Client security questionnaires

Your client's biggest customer sends a vendor questionnaire. Two hundred rows, a due date, and a contract sitting on the other side of it. Nobody at your client wants to own that document.

Own it. Charge for it. Then keep every row where the honest answer was "no" or "we think so." That list is your roadmap for the next twelve months, written by their customer instead of by you.

A compliance deadline with a real date on it

CMMC for defense suppliers. PCI DSS for anyone taking cards. SOC 2 for a client trying to sell upmarket. HIPAA for the clinics. These come with dates, and dates create budget in a way that abstract risk never does.

Get the details right. PCI DSS requires penetration testing and segmentation testing on a defined cadence for in-scope environments. SOC 2 doesn't name a pentest anywhere in the Trust Services Criteria, but auditors routinely ask for one as evidence supporting the risk assessment and monitoring criteria. Knowing which is a requirement and which is a convention keeps you credible.

An incident at a peer

When a firm two towns over gets ransomed, the whole vertical reads about it. That window is short. A week, maybe two.

Have something ready to send. Not a scare email. A short note on what likely happened at a technical level, what you already do about that in their environment, and the one thing you don't do yet.

Open the conversation without sounding like a vendor

Bad version: "We're excited to announce our new security offering." Nobody has ever been excited about that sentence.

Better version, at the QBR, in the last ten minutes after the ticket review is done.

"One thing before we wrap. We've kept your systems running well this year. What we've never done is check whether somebody could get in. Different jobs. I'd rather find that out on purpose than by accident, so I can bring in an independent team to spend a week trying, and you'd get a report you can hand your insurer."

Then stop talking.

Four things happened there. You separated uptime work from security work, you set up independence, you named a deliverable they can use elsewhere, and you never asked for a budget number. Let them ask about price. They will.

The pentest is the wedge, not the whole sale

This is where MSPs lose deals. They try to sell the entire security program in one motion. EDR, SIEM, awareness training, a vCISO retainer, policy work. A five-figure annual commitment, presented to somebody who showed up expecting to talk about laptops.

Don't. Sell the assessment first.

A scoped penetration test is the right wedge for four reasons. It's finite, so it doesn't need a committee. It's independent, which is exactly what insurers and enterprise customers keep asking for. It produces a document. And it generates the next several projects out of findings that came from a third party instead of from the guy who wants to sell them something.

That last one is the trick. When a report says a domain admin credential was sitting in a file share and lateral movement took under an hour, you stop being the vendor. You're the person helping them fix it.

This is why white-label matters. Under a white label pentesting arrangement the work gets done by people who test every day, the report carries your logo, and your client never meets another security firm. You keep the relationship and the remediation revenue, which is where the recurring money actually lives.

If you've never read a real deliverable end to end, go look at a pentest report template first. You'll pitch it better once you know what lands on the table.

Packaging and pricing that survives a real conversation

Custom quotes kill deals at this size. Your client has to explain the number to a partner or a spouse, and "it depends on scope" never survives that retelling.

Publish three packages internally and quote from them. Adjust for size, don't reinvent.

PackageWhat's in itWho it's forHow to position it
Baseline checkExternal pentest, attack surface review, credential exposure checkSmall clients, first security spend, renewal coming upPriced to clear without a committee. A health check, not a project.
Standard assessmentExternal and internal pentest, Active Directory review, phishing simulation20 to 250 seats, questionnaire or audit pressureYour default. Annual cadence, remediation attached to findings.
Program engagementThe above plus web or cloud app testing, retest, written roadmapRegulated clients, SOC 2 or CMMC, anyone with a hard compliance dateSell the roadmap and the retest. The retest proves the money worked.

Three rules about the numbers.

  • Mark it up and quit apologizing. You're carrying scoping, scheduling, translation into plain English, and the remediation afterward. Real work, real margin.
  • Quote the retest at the same time. Fixing things and never verifying the fix is how the same findings come back next year. Bundle it or price it now, because once the invoice clears nobody wants a second one.
  • Put an annual cadence in the agreement. One test is a project. A yearly test plus a retest is recurring revenue, and it's what insurers and auditors expect to see anyway.

The two objections you'll hear every single time

"We already have antivirus"

You'll hear this from clients, and a version of it from your own techs.

Don't argue product categories. That debate is unwinnable and it makes you sound like a rep. Reframe.

"Antivirus and EDR are how you survive the automated stuff. A pentest is a person deciding to get into your network. Those tools are supposed to catch that, and often they do. The test tells you whether they actually did, in your environment, with your configuration."

Then make it concrete. Plenty of real intrusions never involve malware on an endpoint at all. They start with a valid login. A stolen session token. A service account still carrying a former employee's password. Ask which of those their antivirus flags.

If they still push back, offer the smallest version. One external test. If the report comes back boring, they've bought cheap peace of mind. Reports are rarely boring.

"Our clients won't pay for this"

This one comes from you, not from them, and it's wrong in a specific way. You've decided the price is too high before anybody heard it.

Two corrections.

First, you're comparing the number to your monthly managed services invoice. Your client isn't. They're comparing it to their insurance premium or the contract they'll lose if they can't get through a vendor review. Completely different mental shelf.

Second, you're pitching everybody. Don't. Take the ten accounts with a live trigger. A client with a renewal in sixty days and a questionnaire on their desk isn't a hard sell. That's a person who wants this handled.

When somebody genuinely can't fund a full engagement, sell the smaller thing. A documented risk assessment costs less, gets approved faster, and hands you a prioritized list that becomes the next four quarters of work.

Questions MSPs ask before they run this

How do I sell security if I'm not a security person?

You don't have to be. You have to be the one who knows the environment and brings in somebody who tests for a living. Say it out loud. "I'm not the tester. I bring in an independent team and I own the fix list." Clients trust that more than a sudden expertise upgrade from the guy who runs their backups.

Won't a pentest make me look bad?

Only if you position it after the fact. Frame it first. "We're going to find things. That's the point. Some are mine to fix, some are yours to fund, and I'll tell you which is which." Set that expectation and findings become proof you were thorough. Skip it and the first critical reads like an accusation.

One more thing. Read the draft report before your client does. Every time.

What if the report finds something I should have caught?

Own it in the first sentence, fix it before the readout call, show it fixed on the slide. An MSP who finds and closes their own gap looks competent. An MSP caught burying one loses the account.

How often should clients be tested?

Annually for most, plus after any significant change. A new firewall, a cloud migration, a merger, a major application release. PCI DSS sets its own cadence for in-scope environments, and regulated clients often inherit a schedule from a contract. Read the contract before you guess.

Should I resell testing or just refer it out?

Resell it, under your paper. Referring hands your client a direct relationship with another security firm, and that firm now has a standing reason to talk to them about everything else you sell. White-label keeps you in the middle.

Where to start this week

Don't build a program. Pick ten accounts.

Take the ten with the nearest trigger. A renewal, an audit date, a questionnaire, an owner who's been reading the news. Book fifteen minutes with each. Use the QBR opener. Quote off your baseline package and customize nothing.

You'll close a few, you'll find out where the pitch breaks, and you'll have real reports to reference for the next twenty conversations. That's the playbook. The rest is repetition.

When you're ready to scope the first one, get a pentest quote and we'll size it with you. Channel-only, under your brand, and we never contact your client.

Author

Connor Cady

Founder

Connor founded MSP Pentesting after working in the pentest industry and seeing a massive gap in the market. MSPs were being forced to choose between overpriced corporate firms and shady, automated scanners that auditors hate. He built this company to solve that "sticker shock" and give the channel a partner that prioritizes their margins and client relationships.

Join our MSP Partner Program

Want reseller pricing, sample reports, and partner resources?
Book a call with our team to get access.