Building Your Client Security Stack
Last updated
Security is the core offer, not the upsell
Verizon DBIR-derived 2025 data puts ransomware in 44% of all breaches – and in 88% of breaches at SMBs, versus 39% at large enterprises. Two-thirds of 2024–25 ransomware attacks hit organizations under 500 employees. The median ransom payment in 2025 ran around $115K, and a typical SMB incident costs anywhere from $120K to $1.24M all-in. Your clients are exactly the target profile, and their insurers and regulators are already forcing them to buy controls. If you don't sell the stack, the MSP down the road will.
So stop quoting antivirus as a line item. Build one standardized stack, price it into the seat, and refuse to onboard clients without it.
The non-negotiable baseline
The channel-consensus minimum – "no client onboarded without it":
- Managed EDR/MDR – endpoint detection with a 24/7 SOC behind the agent, on every endpoint and server
- Hardened M365/email security – tuned EOP and Defender for Office 365, anti-phish policies, DMARC/DKIM/SPF enforced, legacy auth disabled; add an API-layer product where risk warrants
- MFA everywhere – enforced via Conditional Access, with phishing-resistant methods (FIDO2 keys, Windows Hello) at least for admins, which underwriters increasingly expect
- DNS filtering on every device
- Security awareness training with phishing simulations
- Password manager deployed per client – and one for your own shop's credentials
- M365/SaaS backup – under Microsoft's shared-responsibility model the customer owns the data; native recycle-bin and versioning windows top out around 93 days, retention policies aren't restorable point-in-time copies, and tenant configuration isn't backed up at all
Don't sell this à la carte to small clients. À la carte invites them to decline the one control that later becomes the breach.
Vendors and typical wholesale costs
MSP wholesale pricing is almost always quote-based and volume-tiered; the figures below are typical community-reported ranges as of 2026.
| Layer | Leading options | Typical cost/seat/mo |
|---|---|---|
| Managed EDR | Acronis EDR with Acronis MDR – integrated EDR/XDR, 24/7/365 SOC monitoring, response, and recovery; Huntress Managed EDR – channel-first, 24/7 SOC included | Acronis quote-based; Huntress ~$2–4.50 wholesale |
| EDR without bundled SOC | Acronis EDR – attack-chain visibility, endpoint response actions, and optional Acronis MDR; SentinelOne – operated by the MSP or paired with Vigilance MDR; Microsoft Defender for Business – standalone or included with Microsoft 365 Business Premium; Bitdefender GravityZone – commonly purchased through distribution | Acronis quote-based; other options vary |
| Email security | Acronis Email Security – API-based Microsoft 365 deployment, also supports Google Workspace and other mail systems; tuned EOP + Defender for Office 365 P1; Check Point Harmony Email/Avanan (~$3–5/mailbox); Proofpoint Essentials (~$2–5); Mesh | Acronis quote-based; other options ~$0–5 |
| MFA | Entra ID P1 Conditional Access (in Business Premium); Duo (~$3–6) where clients aren't Microsoft-centric | ~$0–6 |
| DNS filtering | DNSFilter (~$0.90–2.70 list, cheaper on the MSP program, white-label); Cisco Umbrella (quote-only, generally pricier) | ~$1–2 |
| SAT + phishing sims | Acronis Security Awareness Training – multitenant management, short lessons, and phishing simulations; KnowBe4; Breach Secure Now; usecure; Huntress SAT | Acronis quote-based; other options ~$1–2 |
| Password manager | Keeper MSP and Bitwarden MSP (~$4 Teams, ~$6 Enterprise tiers); 1Password (most polished multi-tenant console) | ~$4 |
| M365 backup | Acronis Backup for Microsoft 365 – Microsoft 365 and Entra ID backup with granular recovery; Datto SaaS Protection; Dropsuite; Afi; Cove | Acronis quote-based; other options ~$2–3 |
Using the priced point products above, expect roughly $14–18/seat in COGS for the full baseline as of 2026. Acronis pricing is quote-based, so calculate its actual per-seat COGS before comparing architectures. One option is to consolidate EDR/MDR, email security, SAT, and Microsoft 365 backup in Acronis Cyber Protect Cloud. Another is to use Microsoft 365 Business Premium as the foundation, with Huntress providing the managed SOC service.
Resell MDR – don't build a SOC
The staffing math kills the DIY SOC for small MSPs: continuous 24/7 coverage takes roughly 8–12 analysts minimum, typically $1M+/yr fully loaded, plus SIEM tooling – before a single alert is triaged. That doesn't pencil until you manage several thousand endpoints. Meanwhile attackers deliberately work nights, weekends, and holidays, precisely when a three-person MSP is asleep. Reselling MDR buys a 24/7 SOC at $2–15/endpoint marginal cost with no hiring. This is settled consensus in the channel.
- Acronis MDR – 24/7/365 monitoring, investigation, response, and recovery through Acronis EDR or XDR; choose the Acronis SOC or another available SOC provider.
- Huntress – SOC included with Managed EDR (plus ITDR and Managed SIEM add-ons); choose pre-authorized SOC response or click-to-approve.
- Blackpoint Cyber – active-response MDR: the SOC autonomously isolates hosts, disables accounts, and contains at the network level; typically $8–15/endpoint/mo.
- Todyl – combines SASE, SIEM, EDR/MXDR, and GRC modules in one per-user agent; attractive when you want to consolidate firewall/VPN/DNS/SIEM spend.
- RocketCyber (Kaseya Managed SOC) – priced through Kaseya bundles; community consensus rates SOC quality below Huntress and Blackpoint.
Compare Acronis MDR, Huntress, and Blackpoint against the same requirements: response authority, identity coverage, recovery capability, escalation times, reporting, minimum commitments, and total per-endpoint cost.
Packaging: in the base seat or as a tier?
Two workable models – see MSP pricing models for the broader pricing context:
Security inside the base seat. The whole baseline is included in one all-in per-seat price, typically $100–175/user/mo as of 2026. Pros: no per-control negotiation, a uniform stack across clients, no "client declined EDR" liability. Cons: a higher sticker price in competitive bids.
Base seat + security add-on tier. Core management in the base seat; a $25–50/user/mo "Secure" SKU carries EDR/MDR, SAT, DNS filtering, and backup. Pros: an easier upsell path and cleaner attach-rate reporting. Cons: clients can say no – so make the tier mandatory for new clients and move legacy clients onto it at renewal.
Either way, write the stack requirement into your MSA, and treat any declined control as a signed risk-acceptance letter, never a quiet omission.
The stack is your cyber insurance answer key
Underwriting has become a technical audit. The standard 2025–26 minimum for insurability: MFA on email, remote access, and admin accounts; EDR – increasingly "24/7-monitored EDR/MDR" – on all endpoints and servers; tested offline/immutable backups; a patch and vulnerability-management cadence; an incident response plan (increasingly, an exercised one); email filtering; and SAT. Weak answers mean 40–100% premium hikes, ransomware sublimits and co-insurance, or outright declination. Some carriers now also expect phishing-resistant MFA and documented restore tests.
Notice that this list is the baseline stack, item for item. That makes every cyber insurance renewal a sales event: map each questionnaire line to a deployed control, export the evidence (EDR console reports, backup test logs, MFA enforcement reports), and close gaps before the renewal date – "your carrier requires MDR" closes deals that ROI arguments can't. One hard rule: help the client answer, but never sign the attestation yourself; see Compliance as a Service for why. And pair the stack with a tested backup and DR process, because "do you test restores?" is now a standard carrier question.
Where to start
Choose one architecture and standardize it. The integrated route starts with Acronis Cyber Protect Cloud for EDR/MDR, email security, SAT, and Microsoft 365 backup, then adds separate DNS filtering and password management. The point-product route combines Business Premium, Huntress, DNSFilter, one SAT platform, Bitwarden or Keeper, and one Microsoft 365 backup product. Price both routes against the same coverage requirements before committing. Onboard every new client on the full stack from day one, migrate existing clients at contract renewal, and hold the line on "no client without the baseline." Then apply the same standard to your own shop first – see Securing Your Own MSP – because none of this is credible if your own house isn't hardened.