SMBs and Security: Avoid a Cookie-Cutter Approach to Selling

By Sara Yirrell

May 5, 2026

Share this post

Cookie cutter paper cutouts in a chain

Did you know that 46% of all cyber breaches impact businesses with fewer than 1,000 employees? According to the same source, 37% of companies hit by ransomware had fewer than 100 employees and SMB employees experience 350% percent more social engineering attacks than those at larger enterprises.

But, despite these facts, many small business owners and CEOs still think they are “too small” to be a prime target and bury their heads in the sand when it comes to cybersecurity, creating a huge challenge for ITSPs selling security solutions.

At ChannelCon EMEA, Christopher Cost, president at C Joseph Consulting, said the key to getting through the layers of anti-security defence is to outthink the small business stereotype and speak their language.

“The argument that ‘we’re too small to be a target’ or ‘I don’t need that on my device’ had more weight four to five years ago when criminal activity and cybersecurity issues were much more targeted and expensive [for the criminals],” Cost said. “They needed to have a very high ROI on their attacks. But now, AI has become a fundamental game changer in these types of technology infiltrations. Things that used to take months, now take hours. And these AI attacks no longer focus on the big guys, they are focusing on any and every organisation that AI can touch, which includes small businesses. Cybercriminals have recognised that they can make even more on a large number of small ROIs,” he said.

Cost added that smaller businesses also tend to understand risk more than governance. They may not even know what governance is unless they are in a very regulated space, and with compliance, many look for an exclusionary statement, or a loophole that allows them to say, ‘it doesn’t apply to me’.

Reframing the Security Conversation for SMBs

As an ITSP, it is crucial to break through these barriers and show these businesses how important it is to invest in a proper cybersecurity posture. Cost said the key is showing SMB owners the impact of security solutions in business terms and avoid IT jargon, adding that it pays dividends to be flexible about pricing at the offset and build a reputation for being a trusted partner that prioritises the customer.

“Make it about the customer’s profit,” he said. “If you don’t help them see their profit, they won’t care about yours. Tie solutions to a visible or recent event and never treat it as a cookie-cutter solution. And it must be turnkey.”

“There are few small businesses that have broken through and matured, but the majority of them, even the ones that are doing something, still suffer from having done it because they were absolutely forced to do it and don’t really appreciate that there is a gain in value,” Cost said.

How can you change up the conversation? Cost says ITSPs can’t keep pushing the same message. You have to speak their language.

“Turnkey cannot be a cookie-cutter solution,” he insisted. “We can’t just take a stamp and say to customers ‘you fit, you fit and you fit’. Turnkey must be something that is still adaptable to their particular business. But more importantly, it needs to be one that addresses something that the small business is immediately aware of; something they think ‘if I address this, I’m going to get these benefits.’ And it must be incredibly affordable because these businesses don’t have spare money to spend frivolously.”

Even though these conversations can be difficult, Costs believes that most small business owners do want to do the right thing.

“We know that our small business customers have their recommendations for why they can’t do things,” he said. “But if we can shift the focus to a turnkey type of solution that is easy, affordable and expandable, then we can come up with a solution that is going to give every business an opportunity to thrive in this cybersecurity-focused world that we live in.”

 ChannelCon EMEA │ 9-10 November │ London │ Register Now 

Related Posts:

The world needs more cybersecurity specialists - and the pay is good. But that's not why successful cyber pros do the job.
By Rich Freeman / Oct 24, 2023

What It's Like To Be a Cybersecurity Specialist for a MSP

Despite the best efforts of antivirus software makers, firewall manufacturers, threat researchers and IT service providers, cybercriminals continue to take a growing toll on their victims. Indeed, cybercrime will do $8 trillion of damage globally this year, according to researcher Cybersecurity Ventures, and $10.5 trillion by 2025.
By Scott Campbell / Feb 11, 2026

From MOTY to CEO: Alex Spigel Takes the Helm with a Focus on Compliance for ITSPs

Technology has always been a big part of Alex Spigel’s life. Some of her earliest memories are playing with old computer equipment at the MSP business run by her father, Steve Rutkovitz. Since then, both her career and the business have developed significantly.