Most MSPs sell security as projects and incidents. The providers growing fastest have moved it into the per-seat line — and phishing protection is one of the simplest places to start.
There is a structural problem in how many managed service providers sell security. The revenue arrives in lumps — an assessment, a remediation, an incident response engagement — and each lump requires a separate conversation, a separate approval and a separate piece of work. Meanwhile the recurring line, the one that actually determines the value of the business, stays flat.
The providers who have solved this did something unglamorous. They moved security from a project category into the per-seat subscription, and they picked services that scale without adding proportional labour.
Three characteristics make a security service suitable for per-seat recurring revenue, and phishing protection at the browser and email layer has all three.
It applies to every user, without exception. There is no argument about which staff need it. Everybody has a browser and an inbox, so the licence count is simply the seat count — no scoping exercise, no negotiation about coverage.
It does not scale your workload. A service that requires an analyst hour per client per month is a service that caps your growth. Prevention that runs quietly and reports automatically does not. Adding the hundredth client costs you approximately what the tenth did.
It produces evidence. This matters more than it sounds. A client renewing a per-seat security line wants to know what they bought. Threats blocked, users protected, domains checked — per client, per period — turns an invisible service into a visible one.
The hardest thing about selling prevention is that success looks like nothing happening. Reporting is not a nice-to-have in this model; it is the mechanism that makes the revenue recurring.
There are two approaches, and the right one depends on your existing agreements.
Bundle it into the base seat. Raise the per-seat price and include protection as standard. This is the cleaner model: no per-client sales conversation, no clients opting out and then suffering the incident you predicted. It works best at renewal or when onboarding new clients, and it removes the awkward position of having a protected tier and an unprotected tier across your base.
Sell it as a named add-on. Keep it as a separate line so the client sees what they are buying. This makes the value visible and the reporting meaningful, but it means having the conversation client by client, and accepting that some will decline.
Many providers do both: bundled into new agreements, offered as an add-on to existing ones until those agreements come up for renewal.
Browser and email protection can be sold together or separately, and clients often have a strong instinct about which they need first. That instinct is usually shaped by whatever went wrong most recently.
A client who lost money to an invoice-redirection attack thinks in terms of email. A client whose staff keep landing on fake login pages thinks in terms of the browser. Both are correct about their own experience, and neither covers the full path — the message arrives in one place and the damage happens in the other.
In practice, starting where the client feels the pain and extending once the reporting is in front of them is more effective than arguing for the full package on day one.
Two mistakes recur.
The first is pricing it so low that it is not worth the operational attention it needs. A security line that generates negligible margin gets neglected, and a neglected security service is worse than no service.
The second is deploying it and never reporting on it. If the client hears nothing for eleven months and then sees a renewal invoice, the line item looks like a cost. If they have seen a quarterly summary showing what was blocked, it looks like a result. The work is the same; the outcome at renewal is not.
The pattern that works is boring and reliable: run it across your own team first, so your engineers have used it and can speak about it credibly. Take one client live end to end and produce the first report. Then extend across the base with pricing and packaging already settled, rather than negotiating each one.
A short introduction covering multi-tenant management, deployment and how the partner model works.
Book a partner introduction →