Every Client You Have Is Secretly Hiding a List of Your Next Ten Clients.
September 23, 2026

Every Client You Have Is Secretly Hiding a List of Your Next Ten Clients.

Your clients are holding onto something more valuable to you than more MRR. Yes, you might be able to convince them that there's another security tool they need to invest in. That might make them safer and bring you a little more revenue and, hopefully, profit to your bottom line. Or they may agree to invest in project work after you explain something to them in your quarterly security briefing (QSB). But there is something even more important to you and them that will have a huge payoff to you if you address it the right way, and will be a huge relief to them once they're aware of the issue.

The windfall? You can stop investing your hard-earned money into schemes and gimmicks to get new leads. What if I told you that you didn't have to spend so much on client acquisition costs? You already have a golden list of likely hundreds, if not more, of organizations that need your assistance, your security assessments, and your help solving their biggest problems. You already have a list of your next ten clients sitting in front of you right now. You've just never looked at it.

This information isn't in your CRM. It's invisible to your team and to your marketing specialist. They're both focused on the leads that are hard to get and hard to convince.

The easiest, slam-dunk new clients are the ones already on this list. The list is their vendor list. Your clients have vendors and suppliers they're super dependent on, and you've probably never asked them about it. You've never had a conversation about that risk and how it would actually impact them. You've never helped them identify which vendors directly have access to their data, the ones I'd consider critical to assess, and they have no idea how fragile that security actually is. Even though your client may be completely dependent on a few relationships, they've never thought to ask about the security behind them. What would happen if one of these vendors went offline? They might be able to find someone else to fill the gap, but at what cost?

By having the crucial conversation about your client's supply chain, you help make sure their core operations stay secure, because their operations are only as secure as the vendors they depend on.

Why your supply chain list is more important than your cold call list

Every name on your supply chain list already has something in common with your client. It could be that they're similar in size. Similar industry. They likely have a similar risk profile. They already have a working relationship with your client, someone you know and who already trusts you. These qualities will never be found in an ice-cold list of leads. Your cold caller or your telemarketing company will have a really hard time establishing you as an authority and an expert. That kind of expertise and credibility is becoming exceedingly important in a super-saturated IT marketplace.

A cold list will get you a list of strangers. This list opens doors quickly with the help of your own clients. You're making their community safer, and you'll have an ally helping you open those hidden doors.

Your super sneaky ninja move to protect more of their supply chain

This is the part where most MSPs fail to get access to their client's entire list of contacts. The way you access this list requires some finesse. You don't start out by asking them directly for a referral. You aren't pitching them on wanting a client like them. You aren't going to give them a bonus or a discount off their bill for bringing you in. You start with a very simple, specific conversation. Most MSPs or IT providers never get to this type of conversation, and it's a major security gap that nearly everyone is blindsided by until something actually happens.

Your secret ninja move starts by asking some very specific questions. The first question is simple: do you know who has access to your systems and data outside of your team? Most clients won't understand or see what you mean at first, so you'll have to give them some examples of upstream or downstream supply chain risks directly touching their data and their team members.

Start them with their financial information. Almost every company has a CPA or accountant with access to critical data, or direct access to accounts, that would be hard to protect from an incident if that accountant doesn't follow good security practices.

Move them off their finances and onto other critical data and systems within their business. Who has access to, or directly interfaces with, which critical processes. First, get them to list out the process, then think through where vendors or outside suppliers interface with those critical processes. Have them call out who on their team interfaces with the vendor, and get them to think about the many holes they actually have in their network that are completely out of their control.

Most MSPs never help their clients map out their supply chain risk, but this is a huge opportunity for improving their security, and an enormous list of opportunities for you. This list could triple your workable leads with just one client's supply chain map. And by doing this exercise, you'll demonstrate a level of value your client never expected you and your team to be capable of.

After they have their supply chain mapped out, identify who should be priorities for you to reach out to. For companies that are too large and complex for you to even want to manage, you can request their SOC 2 Type 2, an easy 15-minute ticket that will be well appreciated by your client. I'd start with three good targets on their list to focus your efforts on. You can run a level 1 Galactic Security assessment on these contacts by following your assessment process. (Note: if you need help solidifying your assessment process, I'd start here: www.builttorunmsp.com.)

These supply chain contacts might have questions about your assessment, which you can easily overcome by explaining what you're doing and why. If you're unsure what they might ask, ask me for the specific objections I've seen. They're generally really easy to overcome, even for the hard-to-crack businesses. You'll also be giving your client an update specifically on whether their supply chain contacts agreed to the simple assessment or not.

By the end of your readout, you'll get a hot lead closing on at the very least some sort of security work, including a third-party quarterly security assessment of their environment with an improvement plan over time.

This process works, and it gets you leads who convert into your security stack. It really doesn't have to be a pulling-teeth situation with those clients who just don't want to invest.

PRO TIP: If you have clients unwilling to upgrade their security to your recommendations, consider spinning the concern into their supply chain and the expectations their supply chain will eventually have of them. Give them a real story of how other clients are already expecting their supply chains to meet specific standards, and how eventually their own supply chain will expect the same of them. This spins the concern from a "will never happen to me" scenario into one that's very pocketbook-centric.

Implement the supply chain conversation into your QSB

The best place for this type of conversation is in your quarterly security briefing. This is the perfect theme this quarter for every one of your clients. If you've never had a security conversation before, spend 5-10 minutes on tickets, then pivot to the fact that you need to introduce something concerning that's starting to pop up. Introduce supply chain risk and get them to see that you're not selling them anything, you just want to make sure they're aware of this risk.

Just like you'd have a conversation about new threats like phishing attacks, you want to get them to realize their supply chain is one of their biggest risks today. It's that simple. You're helping them realize they have a big, hairy problem, then helping them solve it without charging them a dime. At this point, either start mapping their supply chain or schedule a specific meeting to dive into the exercise. Make it top of mind with a follow-up email reminding them of the importance of getting this buttoned up soon.

Then it's your turn to start diving into introductions, three at a time. Get the high-value, high-impact vendors, suppliers, and colleagues that would hurt their bottom line or open the door to major risk.

New Supply Chain Clients WILL Compound Over Time

Realize that by introducing and mastering the supply chain conversation, you'll compound your leads and your growth over time. For every assessment you complete, you should end it by talking about supply chain risk and getting introductions to at least three important contacts in their rolodex they might be concerned about. Push this button hard, and make them name off three top-of-mind contacts right there in the meeting.

As you schedule more and more of your Galactic assessments and readouts, keep getting three more supply chain introductions at the end of each meeting. Your 70-80% close rate will overwhelm your operations team's capacity at first. As you invest in your systems and make things super clean and consistent through programs like builttorunmsp.com, you'll make it easy for them to onboard and service more clients without hiring another employee.

About the author
Adam Kuester

Adam Kuester

Adam Kuester has a PhD in genetics and a career built inside managed services, an unusual combination that shapes how he works. He spent time designing operations at an MSP before joining Bruce McCully to build Galactic Advisors, where he's served as VP of Special Projects. His focus has been operational: finding gaps, building systems, and turning expertise into tools MSP owners can use across a partner base of nearly 1,000 companies. Built to Run MSP is that same work in a different form, practical frameworks for MSP owners who are good at winning business and want to get equally good at running it.