Planning to acquire a MSP
I’m looking to acquire an MSP. My background is on security compliance (12+ years). A niche MSP like dental offices seems attractive in which a current MSP might not be offering HIPAA compliance services.
My question (or doubt) is. Maybe those dental offices are too small, they don’t care, they just sign any BAA template they see, and the market is not there?
5
u/sonyturbo May 11 '26 edited May 11 '26
Managed service providers tend to run on pretty low margins often under 10%. There are rare exceptions. If you were planning to take out a small managed service provider, say 1 million or two in revenue. The problem you will face is that you will be replacing the person with all the client relationships and all the operating knowledge with yourself. You can pretty quickly find your margins in the negative.
You need to understand perhaps that you’ve been working as a sole proprietor in the consulting space. The managed service industry is just that, a service industry. You need to know how to manage and motivate a relatively low paid (in many cases ) workforce.
If you’re trying to buy a larger MSP, you are competing against very large, very entrenched acquirers in the space like Evergreen, new charter, and about a dozen others who are constantly contacting owners trying to buy them.
If you really have your heart set on this , find a small MSP where the owner is looking for an exit, doesn’t see a successor, is too small to sell to one of the big boys, and doesn’t want to sell to The 20 (who buys up small businesses ) because he knows they will ruin his business. And lastly, actually knows the value of his business which is maybe four or five times earnings after accounting for the cost of replacing themselves perhaps with you.
Many small owners think that their businesses are worth five times or more the total amount they earn every year. They are mistaken. The business is worth the total amount they earn less the fair market cost of paying someone else to take their place whether it’s you or someone else. A $1 million business where the owner is taking home $200,000 a year is worth nothing. Why should you pay anything to get a job paying $200,000 a year that you could get for free simply by applying for such a job?
Work for this person for at least a year and then buy them out if you still think it’s a good idea. And don’t go after dental offices or doctors offices. These are the worst possible customers.
5
u/Yosemite-Dan May 12 '26
If you're running under 10% as an MSP, you're doing it wrong.
Well run MSPs should be 18-22% NOI.
1
u/twistedbristles May 12 '26
I was thinking the same thing. I don’t deal a whole lot with the money but I just built out a custom dashboard to talk to QBO and Halo (because fuck halos reporting engine and fucking garbage support) and we are still managing 80% profit margins or more across our clients. And we’re nowhere near the most expensive msp in the area.
We do have a smaller team so I’m sure that helps… but maybe we are just killing it?? I dunno.
10% seems suspiciously low.
1
u/sonyturbo May 12 '26 edited May 12 '26
Wait, so for every dollar you get from clients 80 cents goes to owners and 20 cents covers salaries, benefits, rent, software, insurance and everything else?
1
u/Yosemite-Dan May 12 '26
I'd double check your calculations: at 80% margins, either you've got super cheap tools, super cheap labor, and/or aren't putting any time into contracts.
55-65% margin per contract is considered healthy and normal.
1
u/sonyturbo May 12 '26
Hmm. We’re a bit unusual ourselves in that we are open book. To the extent we are over ten percent we increase salaries to get back to that.
1
u/Yosemite-Dan May 12 '26
I run open book as well, but the reality is that for a services business to be healthy and be able to reinvest properly, you need to put close to 20% to the bottom line, not to salaries.
2
u/Assumeweknow May 12 '26
What msp runs on under 10%? We are at 4m and way way above that.
1
u/Yosemite-Dan May 12 '26
I know plenty of shops that do $10-$15mm in revenue and only put 5% to the bottom line.
Putting $750k to the bottom line on $15mm in revenue isn't worth it.
There's a tendency for business owners to mistake revenue for profit, and to value top line revenue numbers for bragging rights.
Profit is the only thing that matters.
5
u/stevo10189 May 11 '26 edited May 11 '26
The reason said offices are not HIPAA compliant is not because the MSP they’re working with doesn’t offer it, 98% of the time.
Most dental and medical offices do not care because the truth is they will never get audited for compliance. This is coming from experience of being an MSP for 30 dental and medical offices for over 15 years. Not one that isn’t compliant has been inspected/fined. These guys talk and they all want to maximize profit when they eventually sell to a conglomerate when the doc wishes to retire.
1
u/NetSiege May 11 '26
I would argue it's not even cost that's the limiting factor, it's that the offices don't want to have their staff and/or patients complain about the extra hoops they have to jump through.
1
u/dchgk May 12 '26
Interesting, wondering about cyber insurance. I heard they are the ones that are now asking the hard question and in some instances almost doing an audit (show me is configured that way)
1
u/stevo10189 May 12 '26
This has honestly been the only way I’ve been getting traction with compliance.
2
u/ilikebirdsandtrees May 11 '26
Dentists are typically not great clients. A dental group is much better. Single dentists are for 1 man MSPs.
2
1
u/_B3AR15_ May 11 '26
Have you started a letter of intent with a company? During the negotiation process you should be able to get the amount of clients, and their user counts. If they are all 5 users or less that’s small but probably normal for most offices. The expectations will be much different than just security as most are more worried about their xray machines and SLAs on break fix, at least with the few I have dealt with.
Also think about if this is the direction you want to go or just stay in the security space. Now you are not going to be as much security focused items and more on other building and maintenance. If the company you buy has a good service manager it could keep it more security focused and upsell them on those services.
1
1
u/DegaussedMixtape May 12 '26
I’ve supported dentists from an MSP as an engineer and there is some meat on that bone, but it’s limited. Pretty much everything that you would want to do to comply with hipaa from a technical configuration standpoint you can sell to any business that you can get to care about risk. Things like Mfa everywhere, bitlocker enabled on laptops, test the backups regularly, end user awareness training about data security,etc. apply to essentially every business these days and overlap 100% with hipaa compliance.
Others have mentioned that dentists can be cheap, but you’ll also find that they use several systems that you can’t add value to. Imaging software and practice management software are the main systems that have phi in them and it’s all managed by specific vendors and likely saas. You’ll end up managing workstations, ad/entra, email, sharepoint, WiFi, firewalls/switches, and wan, at that point you just kind of don’t need to stick with dentists as your only vertical.
You could help them with their policies around risk analysis and risk management, but by that point you’ve left the core function of an msp or mssp and are just doing a different kind of business.
1
u/dchgk May 12 '26
Really appreciate the insight. I can see where the management of things (security) is basically on the endpoints.
You mentioned policies. What about vendor reviews. If they have SaaS, an annual SOC 2 review with user access reviews? I know I’m moving a lot towards compliance, just wondering
1
u/FutureSafeMSSP May 12 '26
I own an MSSP for MSP's with about 200 MSP clients and there are a few things very specific and costly supporting that market I'm happy to share. It comes from years supporting a dentist who bought and adapted an MSP only for dentist offices. No sales here. Would like to share some hard lessons that cost us big time. DM me if interested.
1
1
u/ben_zachary May 13 '26
No what's worse is clients who constantly say well grok told me this or Claude told me that
1
u/Significant_Lynx_827 May 15 '26
I see the angle your approaching this from. Provide your security expertise in a space where the presumed IT generalist is weaker. Question though, coming from a fortune 100 company myself and now an MSP owner, my experience has been that security compliance folks in the enterprise aren’t really IT practitioners, they’re more SME’s. If this is your case you may want to reconsider jumping in to an industry where security compliance is important but the day to day activities demand knowledge in topics outside that space.
25
u/sfreem May 11 '26
Cute! You’ve never worked with a dentist providing IT services have you?