

You just got out of a great Quarterly Security Briefing meeting with your favorite client where you outlined their biggest risks this quarter and recommendations or considerations to help address concerns. They trust you and are on board with investing in solutions you believe in. You couldn’t ask for more, right?
But there is one more thing that would put you over the moon. You’ve earned the right to ask for it. Referrals. At the end of the meeting you muster up the will to plainly ask. Can you think of anyone who would benefit from working with us.
Your client is definitely willing. She says she’ll think about it. You leave the conversation convinced that you’re going to at very least get a very good hot introduction to a company that will most likely sign up with you. What could go wrong? Your client’s enthusiasm toward working with you couldn’t go any other way.
Two weeks later, nothing. Your client never sent you a lead or even a name. They definitely wanted to, but in just asking for a referral you made it really difficult on them to actually think of who. Who would be the right fit? Who needs IT support services. I haven’t heard anyone asking about IT support, so I guess I just don’t have people in my network needing this right now. Your referral ask fell flat because they couldn’t imagine just recommending your services out of the blue without seeing a real need.
This is where your strategy needs to change. Your referral campaign may occasional muster up somebody, but it isn’t going to be quick or consistent. What if I told you there was a way to not have to dump gobs of money in SEO, AIO or any of the other 3 letter acronyms. What if you didn’t have to pay for expensive advertising or marketing that sometimes feels gimmicky or salesy. Something that makes you a little uncomfortable.
Now, I’m not saying that web searches, paid ads and marketing don’t fit into your strategy. I’ve used all of them successfully and they all have their place. But after spending years focusing on pulling cold leads into my hopper I found a way to get better referrals from people who actually needed my help. The perfect fit.
It wasn’t from pounding the payment or even just asking clients for businesses like theirs. I discovered that the best “referrals” weren’t actually referrals at all. They were supply chain risks that my clients already had in and around their networks and businesses.
Your new approach to asking for a lead.
I want you to flip the script here. Instead of asking for something from your client, I want you to think about how you can simply help them out. Make it easy for them to hand you over a whole list of names. That is what I did to really sky rocket my MSP sales.
I saw a weakness in every client’s security. And that weakness wasn’t from what was on their network. It was from what connected to it.
Brainstorm just for a minute on the types of people your clients deal with.
Colleagues in other businesses or organizations they email frequently?
Vendors that have access to data on their network or that your clients share data with?
People who physically access their building and are around their computers or data?
There is a treasure trove of companies in a variety of niche industries from these simple 4 questions. I’m sure you can come up with a few more than this.
You know for certain that some of these companies are not doing the right thing with their data security—likely because they either don’t understand their risks or because they simply don’t realize that their security impacts others. They don’t realize that by not washing their hands they might make someone else sick. It hasn’t dawned on them. And your client—the one interacting closely with them never realized that they might get sick from something that other business was doing. This is where you have a super power to help them.
How can you leverage this information?
I’ve seen 2 very effective ways to have a meaningful conversation with your clients about supply chain. First, you can simply get them into a Quarterly Security Briefing where you focus on a topic like supply chain for your meeting. You may also review outstanding IT issues or tasks, but the main focus on keeping them up to speed on an issue that is very important to them. One of the biggest issues right now is supply chain, so you can talk about their data, who has access to it, and get them to see they have risks they haven’t been considering. You would bring a few stories from the news about other businesses in their industry who fell victim to supply chain attacks or at very least tell them a few stories about businesses in general having to pick up after a supply chain aftermath.
The point is to get them aware that their data is valuable and others not in their company are a huge gaping weak link to their security.
Next, I would have them think about what critical or sensitive data they have. Obvious ones are payroll and tax data. But they also likely have proprietary data as well. Get them to tell you who has access to this stuff. Lawyers? Accountants? CPAs? Payroll companies?
Those are the easy ins for you to suggest we do an assessment on their networks—and ask for an introduction to get things started.
I wouldn’t stop with the ask. Provide them a simple email for them to share with their client and CC you on the email. Once they sent the email out, you should reply with an email yourself introducing the questions you need answered. You are getting the ball started with some simple instructions. Your client is now seeing that you are taking their security seriously by asking some good questions and their vendor or colleague is also. You are establishing yourself as a committed partner. You offer an assessment at no charge simply in concern for your client. Some may have objections, which you can overcome. Some will dive right in because they want to do the right things by their clients or colleagues.
In doing this exercise, you will have hot leads that understand your value and recognize what you do as something important to more than just their business security. For any assessments you successfully run with, I’d ask at the end for a supply chain analysis of their vendors and correspondences as well.
The cycle builds on itself and you’ve just created an organic way to leverage supply chain risk to build a healthy IT security business.
Now, there is much more to this supply chain system than I could outline here. If you are interested in building out a comprehensive system with metrics, checks and balances, I would encourage you to visit builttorunmsp.com where we have a complete system for building your book of business in easy downhill methodologies like the one I just described here (with detailed emails, scripts and worksheets to help enable your client and their connections to understand the importance of understanding their supply chain risk).
They will keep saying they’ll think about it.
As long as you keep giving them nothing to think about, they will keep saying they’ll think about it and leave it at that. I want you to help me flip the script here and stop asking for referrals. Start finding the gaps and hone in on their supply chain risk as a starting point. The less you are “selling” and the more you are helping the better off we all will be. If you focus on the right things (the helping factors), your business will thrive and your clients will appreciate every second working with you and your team.
Start at builttorunmsp.com.
Frequently Asked Questions
Why do clients say "I'll think about it" when asked for a referral?
Because your ask has no specific business reason attached. The client is being asked to spend social capital with nothing driving the request except your convenience.
How is a supply chain security review different from a referral ask?
It's a legitimate service conversation about the client's own risk exposure. Any referral or expansion that comes from it is a byproduct, not the goal.
Where should this conversation happen in a client meeting?
Inside the security or vendor risk review portion of a QSB, not as an add-on question at the end of the meeting.
Why do unprompted referrals happen more often than asked-for ones?
Unprompted referrals are always tied to a specific moment of visible value. Asking without that specific reason attached rarely produces the same result.
Bruce McCully
Bruce McCully built his first company, an MSP, from zero to $8.5 million in recurring revenue. A significant part of that came from cybersecurity incident response. Going into hospitals at 2am and recovering them from ransomware attacks. He didn't learn what happens when a business is unprepared by reading a case study. He was in the room when it happened. Then he founded Galactic Advisors. He scaled it to eight figures in recurring revenue, then stepped down as CEO to focus on MSP Advancement full time. Not because he lost interest. Because the systems he built meant the company no longer needed him to operate it day to day. He remains Chairman of the Board and majority owner. And now he's doing the only thing he wanted to do all along: helping MSPs level up.