Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Handling Risk Conversations with MSP Customers

N-able
05/12/2026
21
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • MSPs must shift from binary security conversations to risk-focused discussions covering risk identification, tolerance, mitigation, and ownership transfer, as weak customer security creates exponential risk for the MSP itself.
  • Customer segmentation should be based on industry, compliance requirements, company size, data type/volume, and partnerships to determine appropriate security program tiers — not arbitrary bronze/silver/gold structures.
  • Insider risk drives 82% of breaches, making end-user protection the primary design priority for MSP security programs through comprehensive coverage that addresses the human element.
  • Small businesses are three times more likely to be targeted by threat actors than larger organizations because they underinvest in security and MSPs accommodate inadequate protection to avoid losing revenue.

Shifting from Security to Risk-Based Conversations

This presentation reframes how MSPs should approach customer security discussions by focusing on risk rather than binary security status. The speaker emphasizes that weak customer security creates exponential risk for MSPs themselves, making proper program design critical. Rather than asking whether a customer is secure or not, MSPs should focus on risk identification, risk tolerance, risk mitigation, and risk ownership. The conversation centers on how much risk customers are exposed to and how much they want to manage themselves versus transferring to their MSP. This approach acknowledges that 82% of reported breaches involve employee-related causes, making insider risk mitigation a primary design priority for security programs.

Risk-Based Customer Segmentation Framework

The presentation introduces a three-tier risk classification system for MSP customers: high, medium, and low risk. High-risk businesses include those with regulatory compliance requirements (banking, financial, healthcare, education), large organizations with vast data stores, companies with extensive partnerships, or those where a breach could be an extinction event. Medium-risk businesses have attractive data and partnerships but smaller footprints in terms of data volume and company size. Low-risk businesses are typically smaller firms with limited employees, outsourced financial processing, no regulatory requirements, and lower breach impact. However, the speaker notes that CISA findings show small businesses are three times more likely to be targeted than larger organizations, as attackers know these companies underinvest in cybersecurity and MSPs often accommodate inadequate security to retain revenue.

Chapters

0:00 - Program Design Challenges
1:33 - Security vs Risk Conversations
3:05 - Risk Rating Factors
4:56 - Overcoming Customer Pushback
6:20 - Customer Risk Assessment Process
6:58 - High-Risk Business Criteria
8:27 - Medium and Low-Risk Segmentation
9:48 - Small Business Targeting Reality

Key Quotes

0:21 "... weak customer security leads to weak MSP security ..."
1:38 "... the conversation that MSPs really need to be having with their customers really shouldn't be so much on security, but more about risk ..."
2:41 "... 82% of the time, employees tend to be the cause, a lot of the reported breaches ..."
6:06 "... we can no longer absolve clients of their bad decisions ..."
9:48 "CISA's finding that small businesses are actually three times more likely to be targeted by threat actors than larger organizations ..."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Best Practices
  • Getting Started
  • Compliance & Governance
  • Technical Deep Dive
  • MSP Security Program Design
  • Risk-Based Customer Conversations
  • Customer Risk Segmentation
  • Insider Threat Mitigation
  • Security Program Tiering
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Handling Risk Conversations with MSP Customers

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version