In the world of managed services, we often struggle to bridge the gap between technical reality and business decision-making. We know a client’s server is aging or their firewall is a relic, but translating that into a language a CEO understands is a constant challenge. This is where the Client Risk Score becomes the most valuable tool in your account management arsenal.
A Client Risk Score is a quantified representation of a business’s exposure to operational, security, and compliance threats. It moves the conversation away from "patching levels" and "bitrate" toward a clear, commercial discussion about business continuity and liability. It is the metric that turns a subjective technical opinion into an objective business priority.
MSP Agenda was founded by Luis Navarro, following more than 15 years spent building and growing a successful Managed Service Provider. As co-founder of Totality Services, Luis helped take the business from an idea to a highly profitable MSP serving more than 150 clients, eventually leading to an eight-figure acquisition. Luis wasn't the "technical guy"; his strength was sales, growth, and client relationships. He learned that to grow, you must explain complex risks in a way that makes a client feel confident taking action.
Key Takeaways
- Objectivity Wins: A standardised Client Risk Score removes emotion and "salesy" pressure from security reviews.
- Commercial Alignment: It bridges the gap between the technical team's findings and the business owner’s budget.
- Driving Revenue: High risk scores naturally lead to project roadmaps and increased monthly recurring revenue (MRR).
- Liability Protection: Documenting risk scores provides a clear audit trail of what was recommended and what the client chose to ignore.
- Retention Tool: Showing a score decrease over time visually proves the value of your MSP’s ongoing services.
What is a Client Risk Score?
A Client Risk Score is a numerical or categorized value that indicates the current level of vulnerability within a client’s IT environment. It is derived from a systematic assessment of various "risk domains," such as cybersecurity, infrastructure health, data backup, and regulatory compliance. Instead of a pass/fail grade, it provides a spectrum that helps stakeholders understand how close they are to a potential disaster.
For an MSP, this score serves three primary functions:
-
Prioritisation: It tells your technical team where to focus first.
-
Communication: It gives the account manager a "North Star" for the Quarterly Business Review (QBR).
-
Accountability: It places the burden of risk back on the client when they decline necessary upgrades.
| Risk Level | Score Range (Example) | Business Impact | Action Required |
|---|---|---|---|
| Critical | 80–100 | Imminent threat of data loss, total downtime, or legal non-compliance. | Immediate remediation; Emergency project approval. |
| High | 60–79 | Significant gaps in security; lack of redundancy in key systems. | Prioritise in next 30–60 days; Budget allocation needed. |
| Moderate | 40–59 | Standard protections in place, but lacking advanced defences or optimisation. | Address through ongoing roadmap and standard QBR cycle. |
| Low | 0–39 | Environment follows best practices; risks are managed and accepted. | Monitor and maintain; Focus on strategic innovation. |
Why Your Technical Reports are Failing You
Most MSPs provide clients with "Green/Yellow/Red" reports generated by RMM tools. The problem is that these reports are too technical. A business owner doesn't know why a "missing KB450123 patch" matters, so they ignore it. A Client Risk Score aggregates those technical failings into a single number that represents a threat to their bank account, their reputation, or their ability to operate.
Luis Navarro’s experience at Totality Services proved that clients don’t want to be experts; they want to be safe. By translating technical jargon into a commercial risk profile, you stop being a vendor and start being a strategic partner. If you can show a Managing Director that their current score is a 75/100 (High Risk) and a specific project will bring it down to a 30 (Low Risk), the sales conversation becomes much easier.
The Architecture of an Effective Risk Score
To build a credible Client Risk Score, you cannot simply pull a number out of thin air. It must be based on a repeatable framework. If your scoring methodology changes every time you visit the client, you lose credibility. You need to weigh different categories based on their actual impact on the business.
1. Cybersecurity Posture
This is usually the heaviest weighted category. It includes Multi-Factor Authentication (MFA) adoption, endpoint protection status, email security, and user awareness training. In today's environment, a lack of MFA should automatically push a Client Risk Score into the "High" or "Critical" territory regardless of how new their servers are.
2. Business Continuity and Disaster Recovery (BCDR)
Risk isn't just about hackers; it’s about uptime. If a client’s backup fails or they have no off-site redundancy, their risk score should reflect that. We evaluate the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) against what the business actually needs to survive a crash.
3. Infrastructure Lifecycle
Old hardware is a risk. Out-of-warranty servers, end-of-life operating systems, and ancient networking gear increase the probability of a hardware-induced outage. This category helps you drive the hardware refresh cycle, which is essential for MSP profitability and client stability.
4. Compliance and Data Governance
For clients in healthcare, finance, or legal sectors, risk is often tied to regulation. A lack of encryption on mobile devices or improper data retention policies carries heavy financial penalties. Including this in the score ensures you are protecting the client’s legal standing as much as their data.
How to Use the Risk Score to Drive Commercial Growth
The primary reason most MSPs stay stagnant is that they struggle to sell projects to existing clients. They wait for things to break before suggesting an upgrade. Using a Client Risk Score changes the dynamic from "reactive fixing" to "proactive risk management."
The QBR Transformation
Imagine a QBR where you don't talk about ticket counts. Instead, you open the meeting with the Client Risk Score. "Last quarter, you were at a 65. Because we implemented the new firewall, you are now at a 52. However, to get you below 40, we need to address the legacy file server."
This approach does three things:
-
Visualizes Value: The client sees the impact of the money they already spent.
-
Creates a Roadmap: The next project is a logical step to reduce a number, not just an "extra cost."
-
Establishes Authority: You are managing their business risk, not just their computers.
Closing the "Decision Gap"
We’ve all had those clients who simply refuse to follow recommendations. They won't buy the backup; they won't sign up for the SOC/SIEM. By assigning a Client Risk Score and documenting it in a formal report, you create a paper trail. If a breach happens, you can show that you flagged the risk months in advance. Interestingly, when clients see a high score in writing, they are far more likely to approve the project to avoid the liability of "knowing and doing nothing."
Step-by-Step Guide: Implementing a Scoring System
You don't need a complex algorithm to start. You need a consistent process. Follow these steps to integrate risk scoring into your MSP operations:
Step 1: Define Your Weighted Categories
Decide what matters most to your service standard. A typical breakdown might look like this:
- 40% Security: MFA, EDR, Firewall, Phishing Training.
- 30% BCDR: Backup success, recovery testing, off-site copies.
- 20% Lifecycle: Age of workstations, server warranty, OS versions.
- 10% Policy: Acceptable use policies, password rotation, compliance audits.
Step 2: Conduct the Assessment
Use your technical team to gather the data, but use your account management team to review it. The technical team might see a "Server 2012 R2" as a technical debt, but the account manager needs to see it as a "High Risk" item that impacts the Client Risk Score because it no longer receives security updates.
Step 3: Present the "Current vs. Potential" Score
In your proposal, show the client two numbers: their current score and what their score will be after they approve your recommendations. This "future state" visualization is a powerful psychological trigger for business owners who are naturally risk-averse.
Step 4: Track Trends Over Time
A single score is a snapshot; a trend is a story. If a client's risk score is steadily climbing because they keep declining hardware refreshes, that graph is a powerful tool to show them they are heading toward a crisis. Conversely, a declining score proves your MSP is delivering on its promise to protect the business.
Common Pitfalls in Risk Scoring
While the Client Risk Score is powerful, it can backfire if handled poorly. Avoid these common mistakes that Luis Navarro saw throughout his years building Totality Services:
Being overly technical in the explanation.
If you spend 20 minutes explaining how a CVE impacts the score, you’ve lost the client. Focus on the consequence: "This vulnerability allows an outside party to lock your files and demand a ransom."
Using "Scare Tactics."
There is a fine line between identifying risk and fearmongering. If the client feels you are manipulating the score just to sell them something, you lose their trust. The score must be tied to objective facts and industry standards (like CIS or NIST).
Ignoring the Client’s Business Context.
A 10-person creative agency has a different risk profile than a 100-person medical clinic. Your scoring should be somewhat adaptable. A missing encryption policy is a "Critical" risk for the clinic but perhaps only a "Moderate" risk for the agency. Tailoring the impact makes the score feel relevant rather than generic.
The Commercial Reality of Risk
At the end of the day, an MSP is a business that manages other businesses. If you cannot communicate the value of what you do, you will always be viewed as a commodity expense. The Client Risk Score is the vehicle that moves you into a strategic position. When you manage risk, you are no longer just the "IT guy"—you are a business consultant who happens to use technology to solve problems.
Luis built MSP Agenda to solve exactly this. He saw that MSPs were doing great work but failing to communicate it effectively. By standardising the way we review security and risk, we create a more profitable, professional, and sustainable industry. It’s about making the recommendation so clear that the client feels it would be irresponsible to say no.
Advanced Insights: Tying Risk to Insurance and Compliance
In the current US market, cyber insurance premiums are skyrocketing. Many carriers now require specific technical controls just to offer coverage. You can integrate these requirements directly into your Client Risk Score.
If a client lacks a specific control required by their insurance carrier, their risk score should reflect a "Compliance Failure." This creates a secondary pressure point for the client: "If you don't do this, not only are you at risk, but your insurance may not pay out in the event of a claim." This is the ultimate commercial argument for security projects.
| Domain | Sample Assessment Question | Risk Weight |
|---|---|---|
| Identity | Is MFA enforced for all cloud and remote access? | Very High |
| Data | Are backups immutable and tested monthly? | High |
| End-points | Are all machines running supported Operating Systems? | Medium |
| Network | Is there a managed firewall with active security subscriptions? | High |
Frequently Asked Questions
How often should we update the Client Risk Score?
For most clients, a quarterly update during the QBR is sufficient. However, for high-compliance industries or larger accounts, a monthly review of the security domain within the score can help catch emerging threats before they become incidents. The key is consistency; don't wait a year to tell a client their risk has doubled.
Can we automate the scoring process?
Parts of it can be automated through RMM and security tools, but the final Client Risk Score should always have a "human layer." An automated tool might see a missing patch, but it won't know that the client has a major office move happening next week that changes their operational risk profile. Use tools to gather data, but let your experts assign the final meaning.
What if a client disagrees with their score?
This is actually a great opportunity for a conversation. If a client thinks their risk is "Low" while your assessment says "High," it means there is a fundamental misunderstanding of their business dependencies. Use the data to explain the "why." Often, once a client understands the potential cost of downtime versus the cost of the project, their perspective shifts.
Should I show the risk score to a prospect during the sales process?
Absolutely. A "Discovery Risk Assessment" is one of the most powerful sales tools available. Showing a prospect exactly where their current provider is failing them—via a quantified score—creates an immediate gap between their current state and the "safe" state you offer. It justifies a higher seat price because you are providing a higher level of protection.
Does a low risk score mean a client is 100% safe?
No, and it’s important to state this clearly. A Client Risk Score measures the probability and preparedness, not an absolute guarantee. Even a company with a score of 10 can be breached. The goal is to reduce the "attack surface" and ensure that if something does happen, the impact is minimised and recovery is fast.
How do I handle clients who refuse to pay for risk reduction?
This is where the accountability aspect of the score comes in. If a client chooses to remain at a "Critical" risk level, you should have them sign a "Risk Acceptance" form. This document explicitly states that they understand the Client Risk Score and the potential consequences of not acting. Usually, the prospect of signing a liability waiver is enough to get a project approved.
MSP Agenda was designed to make these difficult conversations easier. We believe that when you standardise your security reviews and clearly communicate risk, you build a stronger business. It’s the lesson Luis Navarro learned while scaling Totality Services to a successful exit: focus on the client’s business outcomes, and the technical sales will follow naturally. A Client Risk Score isn't just a number; it's a roadmap to a more secure and profitable relationship.