We're conducting research to understand how MSPs approach vulnerability management and compliance today. Your candid feedback—including what isn't working—will help us make better decisions. This survey takes approximately 15 minutes. Your responses will directly shape how we prioritize features and support partners in delivering these outcomes.

Question Title

1. What's your name?

Question Title

3. What's your company name?

Question Title

4. Total endpoints you manage across all clients

Question Title

5. Number of managed clients

Question Title

6. MSP employee count

Question Title

7. Approximate annual MSP revenue

Question Title

8. What % of your clients have formal security/compliance requirements today? (Insurance requirements, customer mandates, regulatory obligations, named frameworks, etc.)

Question Title

9. Among clients with formal requirements, which show up in your world? (Select all that apply)

Question Title

10. Which 1–3 are most common across your client base, and why?

Question Title

11. Do you currently offer vulnerability management or security assessments to clients?

Question Title

12. Do you currently offer GRC/compliance services to clients?

Question Title

13. Do you have defined recurring services for any of the following? (Select all that apply)

Question Title

14. In the past 12 months, approximately how many times have clients asked about each of the following? (Enter a number for each)

  Never Rarely Occasionally Routinely Constantly
Vulnerability scanning / "Are we exposed?"
Cyber insurance questionnaires / renewals
Proof that controls are in place (MFA, backups, EDR coverage, etc.)
Named frameworks (CIS/NIST/CMMC/SOC 2/HIPAA/PCI)
Third-party/vendor risk questions
"Risk score / posture" reporting (executive view)

Question Title

15. For the topic that came up most frequently, can you briefly describe a specific client request or conversation?

Question Title

16. What typically triggers these conversations?

Question Title

17. Importance (next 12–18 months): How important is it to your MSP's growth to deliver…

  Not important to growth MSP Slightly important Moderately important Very important Critical to growth MSP
Vulnerability management as a recurring service
GRC / compliance management as a recurring service
Attack surface monitoring (external exposure)
SaaS posture management (M365/Google/etc.)
Cloud posture management (AWS/Azure/GCP)

Question Title

18. How well-served do you feel by your current tools/processes in…

  Not at all at all served by current tools/processes. Slightly served by current tools/processes. Moderately served by current tools/processes. Very served by current tools/processes. Completely served by current tools/processes.
Identifying vulnerabilities/exposures
Prioritizing what matters most
Operationalizing remediation (tickets/workflows)
Executive/client-ready reporting for QBRs
Framework mapping / audit readiness (evidence)

Question Title

19. On the spectrum below, where do vulnerability + compliance services fit for your MSP?

Question Title

20. In the next 6 months, how likely are you to…

  Very unlikely},{ Unlikely Neutral Likely Very likely
Standardize on a single vulnerability management approach across most clients
Adopt a dedicated GRC/compliance system (vs spreadsheets/docs) across multiple clients

Question Title

21. Thinking specifically about Vulnerability Management (scanning, prioritization, remediation workflow, reporting): which tools do you use today? (Select all that apply)

  Haven't heard of Haven't looked at Looked at, but don't use Used previously, but no longer Considering Actively Using
ConnectSecure
Nodeware
Rapid7
Tenable
Qualys
Cynet
Galactic Advisors
Cavelo
Augmentt
SaaS Alerts
Kaseya (Network Detective or related)

Question Title

22. Which vendor is your primary?

Question Title

23. For your primary approach, what delivery model do you use most?

Question Title

24. When vulnerabilities are found, how are they handled most often? (Select up to 2)

Question Title

25. Satisfaction with your Vulnerability Management approach

Question Title

26. What are the top 3 ways your current approach falls short? (Pick 3)

Question Title

27. What are the top 3 reasons your current approach works well? (Pick 3)

Question Title

28. Thinking specifically about GRC / compliance management (policies, evidence, audits, controls, framework mapping): which tools/processes do you use today? (Select all that apply)

  Haven't heard of Haven't looked at Looked at, but don't use Used previously, but no longer Considering Actively using
Apptega
Kaseya Compliance Manager
ControlMap
Drata
Vanta
Secureframe
Tugboat Logic
Spreadsheet/docs only
None / not currently offered

Question Title

29. Which one is your primary GRC/compliance tool/approach today?

Question Title

30. What are you primarily using your GRC approach for today? (Select all that apply)

  Never Sometimes Usually Always
Policy management
Framework mapping / controls
Evidence collection & audit readiness
Risk register / risk assessments
Vendor risk management
Client-facing reporting / QBRs
Internal MSP compliance only
Not sure

Question Title

31. Satisfaction with your GRC/compliance approach

Question Title

32. Top 3 ways your current GRC approach falls short

Question Title

33. Top 3 reasons your current GRC approach works well (Pick 3)

G) Platform Expectations

Question Title

34. If a single platform combined vulnerability management with GRC/compliance, how interested would you be?

Question Title

35. What integrations would be essential for you? (Select all that apply)

Question Title

36. If you were in charge of product development and could design the ideal solution for your MSP to deliver vulnerability + risk/compliance services, what would it do?

Question Title

37. What prevents you from having that ideal solution today? (Pick up to 3)

Question Title

38. How do you prefer to monetize vulnerability/risk/compliance services? (Select all that apply)

Question Title

39. Which statement is closest to how you price these services?

Question Title

40. For a recurring Vulnerability Management service (including reporting and prioritization), what monthly price per endpoint would you consider…

Question Title

41. Any additional thoughts or comments you'd like to share related to vulnerability management, compliance/GRC, or how MSPs deliver these services?

Question Title

42. Would you be open to a 20-minute follow-up conversation?

Question Title

43. What's a good phone number?

0 of 43 answered
 

T