Screen Reader Mode Icon
We're conducting research to understand how MSPs approach vulnerability management and compliance today. Your candid feedback—including what isn't working—will help us make better decisions. This survey takes approximately 15 minutes. Your responses will directly shape how we prioritize features and support partners in delivering these outcomes.

Question Title

* 1. What's your name?

Question Title

* 3. What's your company name?

Question Title

* 4. Total endpoints you manage across all clients

Question Title

* 5. Number of managed clients

Question Title

* 6. MSP employee count

Question Title

* 7. Approximate annual MSP revenue

Question Title

* 8. What % of your clients have formal security/compliance requirements today? (Insurance requirements, customer mandates, regulatory obligations, named frameworks, etc.)

Question Title

* 9. Among clients with formal requirements, which show up in your world? (Select all that apply)

Question Title

* 10. Which 1–3 are most common across your client base, and why?

Question Title

* 11. Do you currently offer vulnerability management or security assessments to clients?

Question Title

* 12. Do you currently offer GRC/compliance services to clients?

Question Title

* 13. Do you have defined recurring services for any of the following? (Select all that apply)

Question Title

* 14. In the past 12 months, approximately how many times have clients asked about each of the following? (Enter a number for each)

  Never Rarely Occasionally Routinely Constantly
Vulnerability scanning / "Are we exposed?"
Cyber insurance questionnaires / renewals
Proof that controls are in place (MFA, backups, EDR coverage, etc.)
Named frameworks (CIS/NIST/CMMC/SOC 2/HIPAA/PCI)
Third-party/vendor risk questions
"Risk score / posture" reporting (executive view)

Question Title

* 15. For the topic that came up most frequently, can you briefly describe a specific client request or conversation?

Question Title

* 16. What typically triggers these conversations?

Question Title

* 17. Importance (next 12–18 months): How important is it to your MSP's growth to deliver…

  Not important to growth MSP Slightly important Moderately important Very important Critical to growth MSP
Vulnerability management as a recurring service
GRC / compliance management as a recurring service
Attack surface monitoring (external exposure)
SaaS posture management (M365/Google/etc.)
Cloud posture management (AWS/Azure/GCP)

Question Title

* 18. How well-served do you feel by your current tools/processes in…

  Not at all at all served by current tools/processes. Slightly served by current tools/processes. Moderately served by current tools/processes. Very served by current tools/processes. Completely served by current tools/processes.
Identifying vulnerabilities/exposures
Prioritizing what matters most
Operationalizing remediation (tickets/workflows)
Executive/client-ready reporting for QBRs
Framework mapping / audit readiness (evidence)

Question Title

* 19. On the spectrum below, where do vulnerability + compliance services fit for your MSP?

Question Title

* 20. In the next 6 months, how likely are you to…

  Very unlikely},{ Unlikely Neutral Likely Very likely
Standardize on a single vulnerability management approach across most clients
Adopt a dedicated GRC/compliance system (vs spreadsheets/docs) across multiple clients

Question Title

* 21. Thinking specifically about Vulnerability Management (scanning, prioritization, remediation workflow, reporting): which tools do you use today? (Select all that apply)

  Haven't heard of Haven't looked at Looked at, but don't use Used previously, but no longer Considering Actively Using
ConnectSecure
Nodeware
Rapid7
Tenable
Qualys
Cynet
Galactic Advisors
Cavelo
Augmentt
SaaS Alerts
Kaseya (Network Detective or related)

Question Title

* 22. Which vendor is your primary?

Question Title

* 23. For your primary approach, what delivery model do you use most?

Question Title

* 24. When vulnerabilities are found, how are they handled most often? (Select up to 2)

Question Title

* 25. Satisfaction with your Vulnerability Management approach

Question Title

* 26. What are the top 3 ways your current approach falls short? (Pick 3)

Question Title

* 27. What are the top 3 reasons your current approach works well? (Pick 3)

Question Title

* 28. Thinking specifically about GRC / compliance management (policies, evidence, audits, controls, framework mapping): which tools/processes do you use today? (Select all that apply)

  Haven't heard of Haven't looked at Looked at, but don't use Used previously, but no longer Considering Actively using
Apptega
Kaseya Compliance Manager
ControlMap
Drata
Vanta
Secureframe
Tugboat Logic
Spreadsheet/docs only
None / not currently offered

Question Title

* 29. Which one is your primary GRC/compliance tool/approach today?

Question Title

* 30. What are you primarily using your GRC approach for today? (Select all that apply)

  Never Sometimes Usually Always
Policy management
Framework mapping / controls
Evidence collection & audit readiness
Risk register / risk assessments
Vendor risk management
Client-facing reporting / QBRs
Internal MSP compliance only
Not sure

Question Title

* 31. Satisfaction with your GRC/compliance approach

Question Title

* 32. Top 3 ways your current GRC approach falls short

Question Title

* 33. Top 3 reasons your current GRC approach works well (Pick 3)

G) Platform Expectations

Question Title

* 34. If a single platform combined vulnerability management with GRC/compliance, how interested would you be?

Question Title

* 35. What integrations would be essential for you? (Select all that apply)

Question Title

* 36. If you were in charge of product development and could design the ideal solution for your MSP to deliver vulnerability + risk/compliance services, what would it do?

Question Title

* 37. What prevents you from having that ideal solution today? (Pick up to 3)

Question Title

* 38. How do you prefer to monetize vulnerability/risk/compliance services? (Select all that apply)

Question Title

* 39. Which statement is closest to how you price these services?

Question Title

* 40. For a recurring Vulnerability Management service (including reporting and prioritization), what monthly price per endpoint would you consider…

Question Title

* 41. Any additional thoughts or comments you'd like to share related to vulnerability management, compliance/GRC, or how MSPs deliver these services?

Question Title

* 42. Would you be open to a 20-minute follow-up conversation?

Question Title

* 43. What's a good phone number?

0 of 43 answered
 

T