Skip to content
Revelion

Blog

Why MSPs Lose Pentest Deals to Consultancies (And How to Win Them Back)

MSPs often refer pentest work to consultancies and watch the relationship drift. The reasons are structural, not technical. Here are the four operating-model gaps and the four counter-moves to bring the pentest line back inside the MSP relationship.

9 min readMitch Spicer

A client asks the MSP about a pentest. The MSP refers the work to a consultancy. The consultancy delivers, presents, and stays in touch. Six months later the consultancy is in the boardroom on security strategy and the MSP is back to managing the network. This pattern is more common than the average MSP wants to admit, and it almost never gets lost on technical skill. It gets lost on the operating model behind the offer.

The good news is that every reason MSPs lose the pentest line has a structural fix. The harder news is that those fixes have to live in the way the MSP runs delivery, not in another sales deck. This article walks through the four reasons consultancies win the line, the four counter-moves that bring it back, the metrics that tell you whether it stuck, and where AI pentesting changes the maths.

The framing here is intentionally commercial. We are not arguing that consultancies do bad work. Many of them are excellent. We are arguing that an MSP who refers the pentest out is silently handing over part of the strategic relationship, and that there is now a real path to keeping it.

The Pattern: Client Asks, Consultancy Answers

A familiar sequence sits behind almost every lost pentest line. A managed client mentions a cyber insurance question, an audit prep, or a procurement requirement from one of their bigger customers. The MSP, not wanting to fake capability they do not have, refers the work to a trusted consultancy. The consultancy delivers a clean report, walks the client through findings, and quietly drops a follow-up email two months later asking about the next assessment. By the time the next budget cycle comes around, the consultancy is the one being asked about strategy, posture, and direction.

That drift does not happen because the MSP is bad at security. It happens because the consultancy delivered an asset (the report) that the client now associates with security expertise. The MSP delivered the introduction. The asset wins the brand alignment, and the brand alignment wins the next conversation.

Four Structural Reasons MSPs Lose the Line

When we talk to MSP founders about this, the same four issues come up. None of them are about a lack of security knowledge. All four are about how the work is structured.

  • No evidence stack. The MSP cannot produce an exploit-backed report on demand under their own brand. When a client asks "are we exposed?", the answer involves scoping a third-party engagement.
  • Subcontract branding. The final report carries another company's logo, layout, and delivery fingerprints. The client reads it and remembers the consultancy, not the MSP.
  • Slow lead time. Four to six week scheduling windows are normal in traditional pentesting. Clients now expect security evidence in the same quarter, not the next one.
  • One-off framing. The engagement is shaped like a project quote, with start dates, kick-off calls, and a final report. That shape is the opposite of what a managed service is supposed to feel like.

The combined effect is that the pentest stops looking like part of the MSP's service stack and starts looking like a referral introduction. Even the best MSP relationship cannot fully absorb that.

What Consultancies Are Actually Selling

It helps to be honest about what a good security consultancy actually sells. It is not a pentest. The pentest is the wedge. The product is the relationship that follows.

A typical post-pentest motion includes advisory hours on remediation, retesting after fixes, compliance evidence packaged for the auditor, and a quarterly review of posture. Each of those is billable. Each of those is a recurring conversation. Each of those expands the consultancy's footprint inside the client's security thinking, and most of them are exactly the kind of conversation an MSP is well-positioned to lead.

Consultancies are not winning these accounts because they sell better. They are winning because they walk into the boardroom carrying their own report. The report is the artefact that earns the seat. Whoever delivers that artefact, in their own format, with their own brand, is the one shaping the next conversation.

Four Counter-Moves That Reframe the Pentest as a Service

Each counter-move targets one of the structural reasons. Stacked together, they shift the pentest from a referral line item to a managed service line.

  • Own the evidence. Run pentests in-house through an AI pentesting platform and deliver exploit-backed reports under your own brand. The client reads your logo on the cover, your tone in the executive summary, and your remediation guidance after the findings.
  • Compress the timeline. Days, not weeks. When a client asks for evidence and the answer arrives the same week, the perception of who delivers security shifts immediately. Speed is not a vanity metric here. It is a positioning metric.
  • Productise the engagement. Replace project quotes with monthly assurance retainers. Predictable scope, predictable price, predictable cadence. The client stops thinking about pentesting as a procurement event and starts thinking about it as part of the security service.
  • Stay in the room. Turn each report into the next conversation. Findings become remediation work. Remediation becomes retesting. Retesting becomes the next quarterly review. The MSP, not a third party, is the one carrying that thread.

Deal Lost vs Deal Won

Same client, same ask. Different operating model, different ending. The contrast is sharper than most MSPs realise until they see it side by side.

AspectDeal lost (referred out)Deal won (delivered in-house)
Lead timeFour to six weeksTwo to five days
BrandingConsultancy logo on the reportMSP logo on the report
FrequencyOne-off projectMonthly assurance
Follow-up motionConsultancy emails the client directlyMSP runs the next review under their brand
OutcomeClient meets the consultancyClient stays in the MSP relationship

The lead-time numbers are illustrative. Real-world timings depend on scope, asset complexity, and client readiness. The point is the operating shift, not a fixed benchmark.

Three Metrics That Tell You the Line Is Healthy

A managed service is whatever you measure recurringly. If pentesting is going to behave like a service line inside the MSP, three numbers should be tracked alongside the rest of the managed metrics.

Service-line health metrics

Pentest attach rate

% of managed clients

with at least one pentest in the last 12 months

Retest rate

% of findings

re-validated after remediation

Assurance MRR

recurring revenue

from pentest-backed monthly retainers

Three numbers, one question: is pentesting drifting back to a one-off project, or compounding inside the managed relationship?

Attach rate tells you whether pentesting is part of the standard service stack or an upsell that rarely lands. Retest rate tells you whether you are closing the loop on remediation or just publishing findings into a void. Assurance MRR tells you whether the line is recurring revenue or a project-disguised-as-a-service.

Where AI Pentesting Changes the Equation

The structural fixes above used to be unrealistic for most MSPs. Owning the evidence stack required hiring offensive security engineers. Compressing the timeline required keeping that team busy. Productising the engagement required a delivery model that did not depend on a single human's calendar.

AI pentesting changes the inputs. The repeatable technical work runs through a platform. The MSP still defines the package, reviews the output, adds remediation context, and delivers the report under its own brand, but the engineering bottleneck that historically forced subcontracting is no longer the binding constraint. We covered the unit economics in detail in The Margin Math on Managed Pentesting for MSPs.

The combination of low platform cost, fast delivery, and white-label reporting is what finally lets an MSP deliver the four counter-moves at the same time. Pick one and you have an improvement. Stack all four and you have a service line.

The Bottom Line

MSPs do not lose pentest deals to consultancies because their security skills are weak. They lose them because the consultancy walks out with something the MSP cannot produce on demand: an exploit-backed report under a familiar brand, delivered fast, framed as the start of an ongoing conversation.

The fix is to stop referring out and start delivering under your own brand. Own the evidence. Compress the timeline. Productise the engagement. Stay in the room. Track attach rate, retest rate, and assurance MRR like you would any other service line, and the pentest stops being a referral introduction and starts being a recurring revenue motion.

For the unit economics that make this viable, read The Margin Math on Managed Pentesting for MSPs. For a broader service-design playbook, see The MSP Pentesting Playbook.

See how Revelion helps MSPs deliver AI pentesting under their own brand.

msppentestingpositioningbusiness

Find out what an attacker would reach first.

Request access