How MSPs Win 2027 Security Budget: Plan It, Don’t Pick It

TU0LZJQA1-U0B3VV05084-10fa14008046-512
Diana Wright Publication date: 12 August, 2026
Education

Most service providers learn what a client budgeted for security the same way: in a renewal conversation, after the number is already set. It arrives as a constraint. There’s $40,000 for the year, so what can you do for that?

At that point the work stops being advisory. You’re fitting a security program into a figure someone chose without you, and the only moves left are trimming scope or arguing for more.

What changes the outcome is being in that conversation earlier, before the figure exists, holding something that produces it.

That’s the whole distinction between a planned budget and a picked one. A picked budget starts with a percentage and works down to a shopping list. A planned budget starts with what’s actually broken at a specific client and works up to a cost. Both produce a number, and only one of them survives the question “why this much?”

The 2027 planning season is open now. Over the next few months your clients will decide what they’re spending next year, and most of them will decide it without you in the room.

Why Most Security Budgets Get Picked Instead of Planned

Because a percentage is faster than an assessment, and it sounds like a standard.

Open any guide to building a security budget and you’ll find a benchmark. Common advice puts technology at 3–5% of revenue and security at 15–25% of the IT budget. Other sources say 5–10%, or 7–10%, or 0.5–1.5% of revenue. The ranges are everywhere, they’re offered with total confidence, and they don’t agree with each other.

The disagreement between them is the tell, because a benchmark isn’t a measurement of anything happening inside your client’s business. It’s an average of other companies, most of which look nothing like theirs, applied to a business whose actual gaps nobody has examined. It produces a defensible-sounding figure in about four minutes, which is exactly why it’s popular.

The approach also doesn’t survive a real year. Some 58% of SMBs spent more on security than they had budgeted, and only 7% say their security budget is sufficient. Those two numbers describe the same failure from both ends. Budgets built from a benchmark are simultaneously too small to cover what the business actually needs and too vague to defend when something unplanned arrives, so the year ends in overspend and the client concludes that security is a cost that can’t be controlled.

Your clients aren’t refusing to fund security. They’re funding it badly, because the number was picked before anyone knew what it was for.

When Do Clients Actually Lock Next Year’s Security Budget?

Earlier than most service providers assume, and by someone who probably isn’t your day-to-day contact.

The pattern across the field is consistent, though it’s worth saying plainly that it’s observed practice rather than surveyed fact. Modeling and first drafts happen through the third quarter. Negotiation and trade-offs run into the early fourth quarter. Final approval lands before the new fiscal year opens. If a client runs a fiscal year that doesn’t start in January, the whole sequence shifts with it, so the useful question is never “what month is it” but “when does this client sign off?”

Two details from that pattern matter more than the calendar itself.

The first is that a budget takes weeks to build. Research on annual budget cycles from CFO’s benchmarking puts top performers at 25 days to complete an annual budget, median performers at 32, and the slowest at 56 or more. That study covers finance organizations broadly rather than small businesses specifically, so treat it as directional. The point it makes still holds: by the time a client announces a number, the thinking behind it finished weeks earlier. Showing up when the number is announced means showing up after the decision.

The second detail is who signs, and it reframes the whole conversation. Security budgets get approved by owners, managing partners, and finance leaders, while your day-to-day IT contact is rarely in that room. A prioritized list of technical gaps is the wrong artifact for that audience. A phased plan with costs attached to business outcomes is the right one.

Demand is moving in your favour here. The State of the vCISO research puts high or moderate demand for strategic cybersecurity planning at 85%, up 14 percentage points in a single year. Clients across the market are asking for this conversation. The open question is whether you’re the one having it with them.

What Turns an Assessment Into a Number a CFO Will Approve?

Three things: a measured starting point, prioritization by business impact rather than technical severity, and phasing that turns the total into a monthly figure.

Start with why the measurement matters at all. Here’s an uncomfortable finding for anyone who believes planning is inherently valuable: 83% of SMBs say they have a cybersecurity strategy, and their incident rates are identical to those of businesses with no strategy at all. Having a plan changes nothing. Having a plan built from a measured starting point is a different object entirely, and the difference between them is the assessment.

A posture assessment establishes where the client actually sits, which turns an abstract argument about risk into a specific list of gaps with a score attached. That’s the input. The output that matters is a prioritized remediation roadmap, which is where most of the value gets created and where most service providers stop too early. A list of findings is a report. A sequenced plan that says what gets fixed first, what it costs, and what the business gets in return is a budget proposal.

The sequencing is what makes it fundable. Nobody approves an $80,000 security overhaul. Plenty of people approve $3,200 per month for a phased program with visible milestones, which is the same money described in the language the person signing actually thinks in. Frame it monthly, because that’s how your client experiences it and how you’ll bill it.

This is also the moment the assessment stops being a cost you absorb. Some 48% of service providers and cyber advisory practices see risk assessments as an easy upsell driver for other services, which makes sense once the roadmap exists: every phase on it is a service someone has to deliver.

How Do You Run This Across Every Client, Not Just Your Best Two?

By stopping the treatment of it as a bespoke engagement and starting to treat it as one motion applied across the base.

The revenue sitting inside your existing client list is a subject worth reading about on its own, and the case for it is already well made. What’s worth adding here is why the planning season is when that base converts, and what makes running it at scale possible at all.

The economics all point the same way once you look at them. New logos are getting harder to win, with 71% of MSPs now saying acquiring new customers is their biggest challenge, from a survey of more than 1,000 providers. Meanwhile every client already on your books has a 2027 budget conversation happening whether you participate in it or not. The cheapest revenue available to you this quarter is the budget your existing clients are about to allocate somewhere.

Running this across a full book used to be impossible for one practical reason. An assessment that consumes weeks of senior consultant effort can only be delivered to two or three flagship accounts, which is why portfolio-wide planning has stayed theoretical for most providers. That constraint is what’s changed. Some partners report cutting assessment time by roughly half and moving delivery to junior staff, which is the difference between a motion you can run twice a year and one you can run across 60 clients in a quarter.

Scale changes what you can see, too. One assessment tells you what one client needs. Assessments across the whole base tell you where budget is hiding across your book: which gaps recur, which services close them, and what the total opportunity is worth. That’s a different kind of information from a stack of client reports. It’s a revenue map, and it turns planning season from a set of individual conversations into a quantified pipeline you can actually forecast against.

What If Your Client Doesn’t Plan Ahead?

Many of them don’t, and pretending otherwise makes the whole argument easier to dismiss.

Two-thirds of SMBs cite cost as the top barrier to better security. A large share of the market buys reactively, when an incident happens, an audit fails, a customer sends a security questionnaire, or an insurance renewal arrives with new conditions attached. For those clients there’s no tidy planning cycle to get ahead of.

That’s a real limit on the seasonal argument, and it points somewhere useful rather than undermining the case. A client with no formal budget process has no incumbent number to displace. When you bring a measured plan to a business that has never built one, you aren’t competing with their existing figure. You’re supplying the only structured input in the room, which is a considerably easier conversation than arguing someone out of a number they already committed to.

The practical answer is to sort your base rather than work it evenly. Some accounts will plan, have the maturity to act on a roadmap, and are worth a full planning conversation this season. Others need a reactive trigger, and your job with them is to be ready with a plan when the trigger arrives. Grading your client list before you start is the difference between a focused eight weeks and 60 conversations that go nowhere.

Where to Start If You’re Reading This in August

Start with your client list rather than your service catalogue. The window between now and the end of the fourth quarter is enough time to run this properly, provided the first move happens in the next couple of weeks. A workable sequence looks like this.

TimingMoveWhat you walk out with
NowGrade the client base by maturity and budget authorityA shortlist of accounts worth a planning conversation this cycle
Next 2–3 weeksRun assessments on the shortlistPosture scores and specific, prioritized gaps per client
Weeks 3–6Build phased roadmaps with costs attachedA monthly figure per client, in business language
Weeks 6–10Take it to whoever signsA funded 2027 line item, agreed before the budget closes

None of that requires a new service offering or a hire. It requires starting before the client’s finance conversation instead of after it, and having something to bring that a percentage benchmark can’t produce.

The number your client sets for 2027 is going to be set by someone. The only real question is whether it gets built from what their business actually needs, with you holding the pen.


At Cynomi, we built the Security Growth Platform to make exactly this motion repeatable: CISO Intelligence that turns assessments into prioritized, fundable roadmaps, and portfolio-level revenue insight that shows where next year’s budget is sitting across your entire client base. We carry the complexity, so you capture the budget.

Explore the 2027 Readiness hub to get The Service Provider’s 2027 Budget Workbook.