Exposure management, Managed Security Services, MSP, MSSP

From Provider to Advisor: The MSP Shift Toward Risk Leadership

Guest blog courtesy of WatchGuard® Technologies.

Most MSP client reviews are a record of activity. The endpoint agent was deployed. The firewall rules were tuned. Tickets were closed inside the SLA. For years, that was enough to hold an account.

That is not the question being asked anymore. Boards, cyber insurers, and auditors have converged on a different one: what are this business's current security and compliance risks, and who is accountable for them? This question has no ticket number. The partner who can answer it clearly, in business terms rather than product terms, stops being a supplier and becomes an advisor.

Key findings from the WatchGuard MSP Survey 2026:

  • Nearly half of SMB and midmarket organizations already describe their provider as a strategic advisor or proactive partner rather than a technology supplier.
  • 58% expect to change providers within three years.
  • The gap between deploying technology and managing risk is where the next round of contracts will be won or lost.

Read those numbers together and the picture is clear. Advisory positioning is becoming the norm, and a large share of the install base is in play. MSPs who stay in deployment-and-maintenance mode end up competing on price against a peer group that is competing on outcomes.

What Is Risk Leadership?

Risk leadership is not a new product line or a separate service tier. It is a discipline layered onto work the MSP already performs: taking the technical reality of a client environment and translating it into a ranked, defensible account of business exposure.

The distinction matters because the two outputs sound similar, but land very differently. A vulnerability report says a server is missing patches. A risk statement says an unpatched line-of-business server carries the highest likelihood of a ransomware event in the environment, that the current backup configuration would put recovery at several days, and that a specific control would cut that window materially. One is a finding. The other is something a board can act on and an insurer will recognize.

The Three Motions of a Risk Practice

Providers who make this shift successfully tend to build it on three repeatable motions.

Evaluate and rank. Identify the risks the client carries today and order them by likelihood and business impact rather than by CVE severity score. Ranking is the part clients cannot do for themselves, and it is the part they remember.

Demonstrate reduction. Show the same exposure with and without controls in place. When a client can see the delta, the security stack stops reading as a cost line and starts reading as a measurable risk reduction. This is also the single most effective renewal and upsell conversation available to a provider.

Manage over time. Re-run the evaluation on a set cadence so the client can see the trend. A single assessment is a project. A recurring evaluation is a practice, and it is what supports both the roadmap and the price.

How to Build Risk Evaluation into Reviews and Pricing

The operational question is where this work lives. For most MSPs, the answer is the quarterly or semiannual client review, which already exists on the calendar and already has the right people in the room. Replacing the ticket retrospective with a ranked risk view changes the character of that meeting: it becomes a forward-looking discussion about exposure, priorities, and budget, which is the conversation the client's leadership is already having internally without the provider present.

Pricing follows naturally. Once exposure is documented and ranked, the recommended controls are not a line-item upsell. They are the answer to a risk the client has already agreed is real and already seen quantified. Providers who run this motion consistently report shorter approval cycles on security spend, because the justification arrives before the quote does.

Join the Live Webinar

September 22, 2026 at 8:00 AM PDT (3:00 PM GMT) | 60 minutes, including live Q&A

Mick McCarter of WatchGuard® and Aaron Fansler, CEO of FrontLine Cyber Solutions, are hosting a practical session on risk evaluation: how to assess and rank the risks a client faces today, how to demonstrate that those risks are reduced once controls are in place, and how to manage them over time.

In this webinar, you'll learn:

  • How to evaluate and describe a client's risk exposure
  • How to show a client the difference in exposure with and without controls in place
  • How to build risk evaluation into client reviews and pricing

Register for the webinar

Your clients are already being asked to account for their risk. The partners who can answer that question will keep those accounts and grow them.

WatchGuard® is a registered trademark of WatchGuard Technologies, Inc. in the United States and/or other countries.

You can skip this ad in 5 seconds