5 Strategies for Risk Reports that Make Clients Move

By Jennifer Oladipo

Mar 26, 2026

Share this post

Man presenting data to clients

You spent hours scanning networks, compiling data and building a comprehensive risk assessment. You present it to your client. They nod politely, say "thanks," and then ... nothing. No urgency. No budget conversation. Just a PDF collecting digital dust in their inbox. They’re letting you know they don’t care, and it’s up to you to change that, says Cytracom COO, John Tippett.

"The risk report itself does not create value," Tippett says. It should be used to start a conversation. But many ITSPs treat it like a deliverable instead of a tool. As a result, risk reports get ignored for several reasons:ChannelCon_2025_The Risk Report Your Clients Will Actually Read_ 15

  • Leaders don't believe their current state is actually a problem.
  • Your need to explain every detail derails the conversation.
  • Jargon blocks understanding (and clients won't admit it).
  • Data overload paralyzes instead of motivates.

However, ITSPs who better understand the client’s mindset and thoughtfully reframe the conversation can get clients to not just pay attention, but also take important action.

Realize You're Fighting Human Nature

Before you can fix the delivery, you need to understand what you're up against. And it's not ignorance or apathy. It's biology, Tippett says. "We all have a scary condition called metathesiophobia," he says. That's the fear of change and new things, and humans are hardwired for it. "We sit at the same place in the lunchroom. Or if you don't, it's because you feel like you're always supposed to be meeting somebody else, so you fear that."

Your clients aren't ignoring your risk report because they don't care. They're ignoring it because doing something about it requires change. And change is uncomfortable. Your job isn't just to inform them, but to move them in spite of fear. "We literally are professional movers," Tippett says. "We have to figure out how to connect and drive change."

Here's how to do exactly that.

1. Remember You're Not Presenting to Yourself

It’s a common mistake: Technical people love technical details and naturally want to share all of them. But your audience isn't you. So, think about who's actually receiving this information. Is it a CFO focused on reducing risk and managing compliance? A CEO worried about business continuity? Or a small business owner wearing all the hats and just trying to keep the lights on? Each of these people need a different message, tone and level of detail.

Tippett shares a story about an eye exam experience where somebody got this right. When the technician started running tests without explanation, Tippett pushed back. "I was like, 'Hold on a minute. What is that thing?' And he said, 'Oh, you're one of those guys.' And then he pivoted completely." The technician slowed down, and in simple language explained each piece of equipment, what it measured and why. "I actually went and wrote a positive review about this man," Tippett says. "He totally pivoted his pitch. I'm going back forever. I don't even know if what he's telling me is right. I'll look it up later. But man, I feel really good right now." Your clients want that same experience. They want to feel informed, not overwhelmed. They want to understand enough to trust you, even if they don't grasp every technical nuance.

2. Establish Credibility Before FUD

Too many ITSPs jump straight into the findings, listing vulnerability after vulnerability, threat after threat. And then they wonder why clients seem paralyzed instead of motivated. Before diving into the scary stuff, you need to establish that you're the person who can fix it. "You have to let them know: Don't worry, this can be fixed, this can be solved, I'm so glad you called me," Tippett says.

Client mindset matters here, too. For a CEO who's already working with an MSP a 5-out-of-10 risk score might be unacceptable, and you can frame it that way. But for a solo IT person, it’s better to emphasize how impressive it is they've covered this much ground on their own. Then offer to take them further.

You're not just delivering data. You're telling a story. And the story needs a hero (you) who can guide them through the challenge. While fear, uncertainty and doubt (FUD) are necessary motivators, they’re not good reasons for people to do business with you, Tippett says.

3. Translate Everything Into Money

Money is a universal language, and your job is to bridge every finding back to financial impact. "It's either going to make you money, save you money or stop you from losing money. That is the easiest cheat code," he says.

A common way to make findings concrete is to calculate risk per hour using this formula:

Annual Revenue ÷ 2,080 = Revenue Per Hour

That 2,080 number represents generally accepted annual business hours (52 weeks times 40 hours). It's the same math you'd use to convert an hourly wage to annual salary or vice versa.

So, if your client brings in $1.2 million annually and has five employees, that works out to roughly $115 per hour, per employee in potential lost productivity. Now multiply that by an eight-hour outage or a five-day breach impact. Suddenly those abstract vulnerabilities have real dollar signs attached.

Tippett also uses this approach to reframe conversations about affordability. When a client says they can't afford managed services, dig deeper. He notes the amount some clients bill for just an hour of their time could cover half their managed services fee for an entire month.

4. Make it Easy With Colors and Grades

You need to present information in a way that anyone can instantly understand as good or bad. Tippett offers two approaches: "One is colors, and two is grade school. We've all been scarred for life: A, B, C, D, death,” he says.

Color coding gives clients an immediate visual signal. Red means trouble. Green means you're in good shape. No interpretation required. Letter grades have a similar universality, and you can use both methods simultaneously to help clients instantly understand where they stand without needing to parse technical metrics. "When you talk about anything other than that simple format, people can't get their minds around it," Tippett says.

Your rating system won’t be arbitrary but rather based on industry guidance and your own expertise. Combine the grades with the dollar figures from step three, and you've got a powerful one-two punch. "This D in endpoint protection is why you're exposed to a $45,000 ransomware risk" hits very differently than a ten-page vulnerability scan.

5. Keep It Ongoing (Because Someone Else Will)

If you’re doing your job well, clients have no idea how much work you're actually doing. And that makes them vulnerable to competitors who show up with their own assessments. "Somebody is quarterly reviewing your existing clients if you're not," Tippett warns. Regular business reviews aren't just about demonstrating value (though they absolutely do that). They're defensive. When a competitor comes knocking with a free assessment, you want your client to already feel empowered enough to reply, "Yeah, I know about that. We already talked about it. What else have you got?"

Realize that risk reports done well and regularly, will help clients better understand their value in the near- and long terms. You know your risk reports contain valuable information. But information alone doesn't drive action. As an ITSP you need to know your audience, establish yourself as the solution, translate technical findings into financial impact, simplify the presentation and maintain the conversation over time.

GITA members: Access business-building resources on the Member Portal.

Not a member yet? Join now.

Related Posts:

Team of people looking at a computer smiling
By GTIA / Feb 12, 2026

From Control to Trust: Build Motivated, High Performing MSP Teams

Personal responsibility is the key to motivation and performance, according to Kristin Dethloff, trainer and coach at UBEGA GmbH. Helping employees learn how to act independent and learning how to put trust before control can make a big difference in a business’s success, said Dethloff, who spoke about this topic at a recent GTIA DACH Community Meeting in Berlin. In the following interview, Dethloff explains why personal responsibility is an important skill and how companies can use it to increase motivation and performance.
Team of people looking at a computer smiling
By GTIA / Feb 12, 2026

Vertrauen statt Kontrolle: Eigenverantwortung steigert die Leistung von MSPs

Eigenverantwortung ist laut Kristin Dethloff, Trainerin und Coach bei der UBEGA GmbH, der Schlüssel zu Motivation und Leistung ist. Mitarbeitern dabei zu helfen, selbstständig zu handeln, und zu lernen, Vertrauen vor Kontrolle zu stellen, kann einen großen Unterschied für den Erfolg eines Unternehmens ausmachen, sagt Dethloff, die kürzlich bei einem GTIA DACH Community Meeting in Berlin über dieses Thema sprach. Im folgenden Interview erklärt Dethloff, warum Eigenverantwortung eine wichtige Kompetenz ist und wie Unternehmen sie nutzen können, um Motivation und Leistung zu steigern.