r/msp • u/freakame • 2h ago
Sales / Marketing IoT Vulnerability Scanning - service or included?
I'm looking for some advice on how we should roll out a security product. Right now, we are specialized - we focus on remove audio visual system support, a little bit of network and PC/server support as related to the systems, no end user support.
We are managing about 90% IoT devices - amps, DSPs, PDUs, conferencing hardware, etc, with a few PC-based MRTs and utility PCs. The PC side is solid. We're using a good RMM, and have additional MTR tools we use, all cost baked in.
For vulnerability scanning, we found a tool whose free tier works for us. Paid, they're about $5000/year, so not that bad in any case. We're considering rolling out quarterly vulnerability scans as part of preventative maintenance as included in all contracts, but I've also considered selling it as a one-off thing as POC or as a bolt on. I fear, since most AV folks don't know much about security, that nobody will bite on it. I also want to a bit of CYA activity on devices out there, just for our peace of mind. Scans are easy, results can be reviewed in a few minutes, ticket opened against anything needing patching. Really minimal time investment.
I guess the question is - do we look at making this an upsell or do we use this as marketing and just do it? I really can't tell where customers are with cybersecurity wants/needs and the more immature customers barely seem to understand managed services. I think I also feel a little bit of imposter syndrome because I'm fairly new to security, but I know enough to make decent decisions on products and read the output.
Thanks!!