Security as a maintenance window
How to turn the exploited-vulnerability cadence into a service your clients understand and buy.
Last updated: 11 August 2026 10:53 UTC
The trouble with selling security
Security is hard to sell because it is hard to make concrete. It arrives as an emergency, it is priced by fear, and the client cannot see what they paid for until something goes wrong. Patching, by contrast, is a service clients already understand. It is scheduled, it is routine, and it has a clear before and after. The opportunity for an MSP is to make security look more like patching and less like an emergency.
The KEV list gives you a cadence
CISA's Known Exploited Vulnerabilities catalog is the closest thing the industry has to a shared, authoritative worklist. When a vulnerability lands on it, someone is provably exploiting it in the wild. That is a defensible reason to act, and it arrives on a steady rhythm rather than all at once. A handful of new entries a week is a workload you can plan around. Treat “patch this week's exploited vulnerabilities across every client” as a standard maintenance window, the same way you already treat operating-system updates.
Package it as a recurring service
Give the window a name, a cadence, and a deliverable. Weekly or monthly, you sweep every client tenant for the products on this week's list (the portfolio view does that for you), you patch what is exposed, and you send each client a short advisory that says what you did and why (the client advisory generates that text). The deliverable is not a vague sense of safety. It is a dated list of exploited vulnerabilities you closed before they were used against them.
Why clients say yes
Clients buy predictability. A recurring security maintenance window turns an open-ended worry into a line item with a clear scope and a visible output. It is easier to approve a standing service than an emergency, and it is easier to renew a service that produces a monthly artifact the client can hand to their own board or auditor. You are selling readiness, not fear, and readiness renews.
The economics work both ways
The same cadence that protects the client pays the MSP. The KEV list scopes the work, so the effort is bounded and repeatable. The advisory and the portfolio sweep are already produced for you, so the marginal cost per client is low. And because the service is tied to an external, authoritative source rather than to your own alarm, it holds up under scrutiny. Revenue for you is the byproduct of a client who is genuinely more covered, which is the only kind of security revenue worth building on.
Security does not have to be sold as a crisis. Built on the exploited-vulnerability cadence, it can be sold the way you already sell maintenance: scheduled, scoped, and renewable. That is better for your margins, and better for the clients who most need someone watching the list for them.