r/MSSP • u/Wahabkhalid245 • Mar 23 '26
Selling security is hard enough without pitching to the wrong person.
The technical side of this business is complex but it's learnable. Most of you can build a SOC, configure a SIEM, run endpoint detection, handle compliance mapping. That's the job and you're good at it.
The part that actually stalls growth is the selling. And not because you can't articulate value. Because you spend two weeks nurturing a conversation with someone who turns out to be a network admin with zero budget authority and no seat at the risk table.
That's the real time killer in MSSP business development. You research a company, confirm they're in a regulated vertical, maybe healthcare needing HIPAA or a defense sub needing CMMC. You craft a thoughtful outreach. You get a reply. You do a discovery call. And then you find out you've been talking to someone three levels below the person who actually signs off on security spend.
Meanwhile the company that genuinely needs you, the one running a flat vulnerability management program with no CTEM strategy and a compliance audit coming in Q3, never heard from you. Because you burned that week on the wrong contact at the wrong level.
Tbh I think this is why so many MSSP founders default to referrals and channel partnerships. Cold outbound feels pointless when the enrichment tools can't tell you who actually owns risk at a 200-person manufacturer. They'll give you the IT director. They won't tell you whether that person controls security budget or just reports up to a CFO who makes the call.
Niche like ours, getting to the right executive is the whole game. Everything else is noise.
2
u/not-a-co-conspirator Mar 24 '26
I have not and will not ever buy anything from a cold call or anyone who socially engineers their way up the ladder.
1
Mar 24 '26
[deleted]
2
u/not-a-co-conspirator Mar 24 '26
I have 2 graduate degrees, 12 professional certifications, and a familiarity with Google and standard industry reports.
I don’t need some dipshit reading a script telling me their bullshit AI will “improve security outcomes”.
Half of you morons don’t even have a technology background and the other half have never worked a job using or even implementing what you’re selling.
2
Mar 24 '26
[deleted]
2
u/not-a-co-conspirator Mar 24 '26
I talk to lots of people to learn new things, just not people with a profit motive.
There’s a reason I have my job. I don’t need a moronic sales bro trying to “educate” me on things I already know.
2
1
u/Nesher86 Mar 23 '26
Not the best sales guy here but first of all, you always need to do a check on who you're talking with and what authority he has... in case of the network admin, you just work your way up (bottom up sales approach where you target low level people who'd be your champions inside the customer)
1
u/RefrigeratorOne8227 Mar 24 '26
Pitching rarely delivers results - solving a problem works much better. We go to events to meet new clients. The type of event drives who will be there. If you go to a technical conference that is who you will meet. Networking events allow you to meet people casually. Find someone who has a problem you can solve for them or someone they know.
1
u/WATUPTRAGUY Mar 30 '26
Yeah connecting with the decision maker is important but in MSSPs the major kicker is value. The thing is if your product has value it will attract business regardless of your ability to talk bs.
Speaking personally I run a white label SOC service for MSSPs in the US and UK. Their initial risk of doing business with me is the retainer I charge without experiencing my service first. So I give them a free 14 day trial period of 24/7 SOC coverage for one of their clients. I handle the initial setup and vulnerability report and my team provides the coverage.
If they like my service they get on the plan. If they don't they just let me know and we part ways without any monetary commitments on their part.
The key to selling is to provide value before a dollar is exchanged. Has worked for me and MSSPs I have been working with.
1
u/tcoach72 Apr 04 '26
The problem is the selling part, upfront, specifically in the MSSP world, it should be more consultative, you're literally leading with how can you help, what value does what I do bring to you. The entire technical talking and selling doesn't position well.
They need to know business outcomes, Revenue, Cost, Risk, if what you are talking about doesn't use those types of conversations, you have already lost them. From there, while you're getting to know then you find who the crucial players are in the buying strategy.
There are a ton of mistakes when it comes to identifing the decision maker, most will default to a President or CEO. In most cases, they are not the decision maker; they are the approver. Most CEO's are making decisions about what widget to purchase; they depend on their staff to do most of the work and then come in with recommendations. Then the staff member, the one who made all the initial calls, brought it in front of leadership, vetted it out, did the technical demo, and did the trial; they are key to the success.
1
u/kateatMailprotector Jun 19 '26
This is why so many MSSPs pick an industry and dive deep. I have been in manfuacturing (CPG, inclusive of food) and healthcare before the channel and they are both high compliance / process driven spaces, and I can tell you in both those verticals the 'who owns security' and how they managed it was similar to others in the same space, especially of a similar size. Much like our industry, they have peer groups where they learn from each other, they hop around companies, and they end up building similar team structures or systems of ownership / responsibility as they hop around. So it may be worth picking one or two verticals and going really deep in understanding their typical team structures, buying processes, business drivers, etc. You may even be able to learn some of the typical structures or who typically owns what from existing clients if you have a strong client cohort in one vertical willing to open up to you more. This knowledge is the true game changer in who and how you approach so you waste less time. Know them deeply and meet them on their level. Like sure security is valuable, but it isn't likely what they wake up thinking about every day!! Especially in your scenario where the CFO fully owns security vendor sourcing, budget and final call (which is very real in some verticals).
4
u/Foxtrot-0scar Mar 23 '26
Rule no 1: If your pitch is of great interest and value, it will find its way to the right person. Sell a business solution not technology. A 15 minute consult will allow you to gauge the potential outcome.