
MSPs describe pipeline as their hardest problem, and the data agrees with them: 71% say acquiring new customers is their biggest challenge, and the share who struggle to prove value early in the sales process has nearly doubled. Meanwhile, the same MSP reporting that number manages 70, 80, or 100 clients, of which maybe 15 buy any structured security service such as a vCISO program, compliance readiness, or managed security add-ons. For most MSPs, the pipeline problem is a visibility problem: the buyers are already under contract, already paying you monthly, and already trusting you with their infrastructure. What is missing is a systematic way to see which of them represent security revenue you are not billing.
The Security Pipeline Hiding in Your Managed Base
Look at the gap between how your clients feel about security and where they actually stand. Across SMBs, 94% of leaders consider themselves knowledgeable about cyber threats, yet only 22% have an advanced security posture. That 72-point spread is sitting in your PSA right now, distributed across the managed clients you invoice every month. Each one of them has coverage holes you can already see from your own telemetry: unprotected endpoints, missing MFA, backup jobs nobody tests, and no formal program tying any of it together.
For a market view of what that inventory is worth, managed security services are projected to nearly double, from $35 billion to $67 billion by 2030. The growth is going somewhere, and the provider best positioned to capture any given SMB’s share of it is the one already holding the contract. That is you, for every client in your base, until the day a competitor’s assessment lands on your client’s desk first.
Your Security Attach Rate Is the Metric You Cannot Name
Ask yourself a question your P&L should be able to answer: of the clients you manage, what percentage buy a security program from you, and what is the monthly revenue gap between that number and full coverage? Most owners can quote their MRR, their agreement count, and their service margins, but cannot quote their security attach rate. There is no public benchmark to hide behind either; the industry has not standardized one, which tells you how few providers measure it at all.
The metric is worth computing before anything else in this piece, because it converts a vague sense of opportunity into a number with a trend. Count the managed clients on any recurring security service beyond the tooling baked into your standard agreement, divide by total managed clients, and note the monthly revenue on each side. Most providers land somewhere that surprises them, on the low side more often than not, and the follow-up question writes itself: what would this number be if every client had at least an entry-level program?
The blind spot has a name: revenue blindness. You know your clients need more protection, you know some of them would buy it, and you have no ranked view of where the opportunity concentrates. So expansion happens opportunistically, when an incident scares a client or a compliance requirement forces the conversation, and the rest of the base stays exactly where it was. Until you measure the rate, you cannot manage it upward, and the difference between 15% and 40% of an 80-client base, at even a modest security tier, is a practice-changing amount of monthly revenue.
Portfolio Security Upsell Is Different From QBR Prep
The standard advice you have probably heard for growing security revenue in the base is to bring risk into the QBR: conduct an assessment before the meeting, present the gaps, and propose the next tier. The advice is sound as far as it goes, and the assessment conversation itself is well understood. Its limitation is the unit of work. QBR-driven expansion is one client at a time, on a calendar cadence, dependent on which account manager prepared how well, and it resets to zero after every meeting.
The portfolio move is a different mechanic. You assess the entire base against a consistent baseline, keep those assessments current continuously rather than quarterly, and rank the results by revenue-weighted gap: which clients have the largest exposure, the strongest budget signals, and the shortest path from finding to billable service. The question changes from “what should I show this client on Thursday” to “which 10 of my 80 clients represent the most security MRR I am not billing, and why.” The first is meeting preparation; the second is a pipeline view of the base, one that allows a two-person account team to work an 80-client portfolio without becoming security sellers.
The two approaches differ on almost every operating dimension, and seeing them side by side makes clear why one caps out and the other compounds.
| QBR-driven expansion | Portfolio approach | |
|---|---|---|
| Unit of work | One client, one meeting | The whole base, continuously |
| Cadence | Quarterly, calendar-driven | Always current |
| Depends on | Account manager preparation | A consistent assessment baseline |
| Output | A recommendation for Thursday | A ranked list of revenue opportunities |
| Ceiling | Number of good meetings per quarter | Size of the managed base |
The distinction matters because the first approach caps at the number of good meetings your team can run, while the second turns every client into a permanently visible opportunity with a number attached. It also changes who can do the work: reading a ranked opportunity list takes an account manager 10 minutes; preparing a defensible security story for one QBR from scratch takes a day, and most teams quietly stop doing it after the third quarter.
An Entry-Level Security Tier for Every Managed Client
The reflexive objection you will hear, sometimes from your own team, is that SMB clients will not pay. The honest reading of the data says something narrower: they will not pay for security shaped like an enterprise program. Only 7% of SMBs call their security budget sufficient, and cost consistently tops the reasons small clients hesitate. The mistake is reading that as a dead end when it describes a packaging problem, and packaging is fixable.
The portfolio answer is an entry-level security tier for every managed client, priced as a monthly line item the way the rest of your agreement already is, with 2–3 steps above it mapped to the gaps your assessments actually find. A client who will never sign a $4,000-per-month program will add $300–500 per month for a baseline posture assessment, a roadmap, and quarterly visibility, and that entry tier does two jobs at once: it converts unmonetized clients into security revenue now, and it generates the assessment data that surfaces who should move up a tier next. Security stops being a product for the compliance-driven few and becomes a lane every client is already driving in, at different speeds.
Run the illustrative math on an 80-client base. Start with 12 clients on security today at an average of $1,500 per month, which is $18,000 in security MRR. Moving 30 more clients onto a $400 entry tier adds $12,000, and graduating even 6 of them to a $1,500 mid tier over the following year adds $6,600 more, all without a single new logo. The numbers are yours to adjust; the structure of the opportunity is the point.
The Security Risk Assessment Is the Conversion Mechanism
The assessment carries the conversion here, because it produces the evidence the client cannot argue with and the ranked findings your team acts on. Providers already know this: among vCISO providers surveyed, 48% call risk assessments an easy upsell driver for other products and services. Partner results show what the motion looks like at full speed. Burwood treats assessments as the first step in an ongoing relationship and converts over 50% of assessed clients into vCISO engagements. Model Technology used the same base-first approach and grew its customer base by 20% while boosting upsell revenue.
Those conversion numbers also say something about effort. Run on a standardized baseline, an assessment stops being a bespoke consulting project and becomes a repeatable unit of work your existing team can execute across the portfolio, which is exactly what makes base-wide coverage feasible for a practice that has no intention of hiring a sales team.
Security Service Expansion Compounds the Client Relationship
There is a second return on all of this that does not show up in the MRR column immediately. Clients buy security from you because they already trust you; delivering it deepens that trust in a way that generic IT support does not. The market data backs the instinct: 92% of organizations will pay a premium for advanced support that integrates their security tools, and 51% rely on their MSP to evolve their security strategy as the business grows. A client whose security roadmap you own is a client who consults you before every technology decision, renews without shopping the contract, and treats your other proposals as advice from their security partner rather than upsell from their IT vendor.
That is the compounding effect: every client you move onto a security tier becomes stickier, more consultative, and more receptive to the next expansion, which is why the practices that systematize this end up growing revenue and retention from the same motion.
Seeing Security Posture and Revenue Across the Whole Base
Everything above depends on one capability: a current, consistent, ranked view of security posture and revenue opportunity across every client you manage. Building that manually means conducting assessments client by client and maintaining a spreadsheet that is stale the week you finish it, which is why most providers never get past QBR prep. This is the problem portfolio-level revenue intelligence exists to solve, and it is where a Security Growth Platform earns its category. Cynomi assesses every client against a consistent baseline, maps each gap to the service that closes it, and ranks the expansion opportunities across your whole base, so your entire team sees the pipeline the way you see the P&L. As Cynomi’s team puts it, the platform shows you where and how to start.
Your next 20 security clients are already on your client list. Start by counting the ones who are not on a security tier today, treat that number as the pipeline report it is, and see how Cynomi turns security conversations into ongoing engagements. The base you already serve becomes the growth you have been hunting for.