In this article, you will learn:
- Why SMB leaders often misunderstand cyber risk
- Why the cybersecurity conversation must extend beyond IT
- How strategic conversations differentiate you
- How will this help your business
- One question you can ask a client this week to start changing the conversation
What CFOs understand about risk and resilience
Once, I asked a CFO of a 200-person manufacturing plant a simple question: “What are your company’s top three digital assets?”
He didn’t hesitate. “We don’t have any.”
I pushed back a little. “What would happen if you were to lose access to your accounting system?”
“Can’t happen,” he said confidently. “It’s in the cloud.”
Then, I asked a question that changed the conversation.
“If someone stole your credentials or hijacked an authentication session and took control of your accounting system tonight, who would you call first?”
Silence.
Then came the blank stare.
“I don’t know. Could that actually happen?”
The surprising part wasn’t that the CFO didn’t know the answer. It was that apparently no one had ever asked him the question.
The real MSP and MSSP opportunity
Like most small to midsized business (SMB) leaders, this CFO had technology providers and IT support, and his company had cybersecurity tools. But he did not have someone helping leadership connect all the technology to business risk.
That’s the opportunity for today’s MSPs and MSSPs.
Credential theft, account takeover and session hijacking are examples of how attackers can exploit the assumptions SMB leaders make about technology. Plus, rapidly evolving AI capabilities are making social engineering, impersonation and fraud more convincing, easier to execute and scalable.
The real issue isn’t whether the CFO understands session cookies. He needs to understand what could happen to the business when a critical system becomes unavailable, sensitive information is compromised, a key vendor is disrupted or an attacker gains control of an important account.
Those are business-risk questions. In many SMBs, no one is asking those key questions.
Time to expand beyond IT
For years, MSPs and MSSPs have built successful businesses at the tactical level. They manage infrastructure, resolve tickets, deploy security tools, maintain uptime and keep systems patched. Those services will remain essential. Since cybersecurity has been viewed as another tactical component of the technology stack, it naturally has fallen within the scope of IT.
Today, cybersecurity is no longer just another product. Cyber risk touches every part of an organization, including operations, finance, customers and insurance. While IT plays a critical role in managing that risk, many of the decisions to manage it need leadership involvement.
IT teams also are being asked to carry more responsibility than ever. In addition to keeping the business technology running, they must keep pace with the evolving threat landscape, third-party risk, compliance requirements and much more. This often taxes an already stretched team.

Karin Fields
More importantly, they don’t have the authority to make decisions about risk tolerance, acceptable downtimes, financial exposure or where the organization should invest. Those decisions belong to leadership.
Bring in the decision-makers
It’s time to expand the cybersecurity conversation beyond the director of IT and bring in leadership.
This doesn’t mean going around the IT team. Quite the opposite. IT can:
- Explain how the backups are configured. Leadership needs to decide how much downtime the business can tolerate.
- Describe how access is controlled. Leadership must identify which operations and information are most critical.
- Recommend technology investments. Leadership must decide how much risk the organization is willing to accept and where to invest.
The opportunity for the MSP/MSSP is to bridge the two. Serve providers can help IT teams translate technology into business impact. They also can help leadership translate business priorities into a cybersecurity strategy.
Conversations with leaders need to focus on risk, business continuity and resilience, not just the technology being used to support them.
Service provider to trusted adviser
Every MSP/MSSP wants to be seen as a trusted adviser by their customers. That position is earned when your customers begin to rely on you for perspective and insight, not just technology.
It starts by changing the conversation. A strategic discussion isn’t about products or a proposal. It requires asking the questions leadership had never considered. These questions will help decision-makers connect cybersecurity to the things they care about:
- Revenue: How long could your company function without its accounting or operational systems?
- Reputation and trust: What information, if exposed, would cause your customers to question whether they should continue doing business with you?
- Business continuity: What absolutely must be operating on Monday morning?
- Financial exposure: What would a three-day disruption cost the business?
- Third-party dependency: What third-party relationships would cause the greatest disruption if it went down?
In the example of the CFO, he wasn’t concerned about the security of his accounting system. He believed it was safe from attacks because it was “in the cloud.” The blank stare came when he understood there were risks that he had never considered.
That realization can spark a different kind of conversation. The MSPs/MSSPs still need to implement, manage and support their customers’ technology. The difference is that the technology becomes the execution layer of a business risk management and mitigation strategy. It’s not the starting point for a sales conversation. That’s how they become a trusted adviser.
How will this help my business?
When leading with products and services, customers can compare features and pricing. But it is much harder for a competitor to replicate your understanding of the customer’s business and ability to help leadership make better decisions.
That difference has economic value. It’s greater wallet share, stronger retention, less price sensitivity, a deeper relationship with leadership and referrals.
One question to ask to change cybersecurity conversations
This week, pick a client and message your IT contact. Ask this:
“Does your leadership team know which digital asset or business systems would hurt the company the most if they couldn’t access it tomorrow?”
If the answer is “not sure,” or “probably not,” you’ve found your opening and your next conversation.
Karin Fields is founder and CEO of Amidot. The company helps SMB leaders directly and through MSP/MSSP partners close the gap between complex cybersecurity and the practical realities of running a business. A former CEO of MicroCorp with a master’s degree in cybersecurity, Fields is known for connecting the right people and getting things done. She founded Amidot to help SMBs build resilience and strength through knowledge.
Featured image: AI generated by ChatGPT













