Skip to main content
MSP sales playbook

How to find and sell your first Cleverer compliance opportunity

A practical sales playbook for Australian MSPs turning existing security relationships into a compliance service line.

Pick the situation you're dealing with below and get a straight answer: who to approach, what to say, which free tool to use, and what happens after they say yes.

What this playbook gets you

1
The right client, first Eight real triggers and a scorecard, so you're not guessing who to call.
2
The actual words Opening lines, discovery questions and objection responses you can use as they are.
3
What happens after yes The full engagement from first conversation to ongoing review, and where you get paid along the way.
Start here

What situation are you dealing with?

Pick the one that matches. You'll get an opportunity read, what to ask, what to say, and what to do next, straight away.

Choose a situation above to see the recommended approach.
Free tools

Two tools, two different jobs

Both are already built into the scenarios above. Here's the general rule so you can make the call yourself.

Cyber Compliance Readiness Check

Use it when there's no clock running. The client thinks they're already covered, you're opening a proactive conversation, or you're reframing after a knock-back. It benchmarks the whole picture, policies, training, roles, registers, evidence, and hands back a one-page action plan.

Open the Readiness Check

Exposure Audit

Use it when there's a live deadline or a public-facing conversation starter, an insurance renewal, a tender, a customer question, an incident. It checks what's externally visible, privacy policy, HTTPS, SPF/DMARC, visible data-collection points, and gives you something sharp to open with fast.

Open the Exposure Audit

Objections

What to say when they push back

The real issue behind each one, and a short response you can use as it is.

What not to do

Eight ways to lose a good client conversation

Don't

  • Lead with "you should buy compliance software."
  • Scare the client with fine amounts.
  • Claim Cleverer guarantees compliance.
  • Claim it gives legal protection.
  • Pitch every client the same way.
  • Open with a rundown of the Privacy Act.
  • Treat Essential Eight as the whole reasonable-steps story.
  • Pitch technical remediation before you've established the business context.

Do this instead

  • Lead with the business trigger, then introduce the tool that solves it.
  • Ask what they'd actually be able to show someone who asked.
  • Talk about reasonable steps taken and evidenced, the real legal standard.
  • Position it as organising the evidence a lawyer or insurer would want to see.
  • Run the scorecard further down this page and prioritise accordingly.
  • Translate what it means for their business specifically, cite the law only if asked.
  • Say plainly that E8 is the technical layer, this is the other half.
  • Start with what they need to demonstrate, then work back to what needs fixing.
Who owns what

The responsibility split, before you're on the call

Know this cold before you talk to a client. It's what stops "we already have an MSP" from being a real objection.

You keep

The technical work

  • Technical advice and validation
  • M365, MFA, endpoint, backup, patching, access, network and email security
  • Implementation and remediation
  • Client guidance and optional reviews
Cleverer covers

The organisational layer

  • Policies and Policy Builder
  • Role based training
  • Asset, vendor and risk registers
  • Evidence, framework coverage, issues and reporting
  • Management review

The client owns the decisions. They approve policies, assign responsibilities, take part in training, supply evidence, accept or remediate risks, and maintain governance. You don't get unrestricted access to their data by running this, and Cleverer doesn't touch your stack.

Where you make money

Six ways this pays, not all on every deal

No engagement produces every line below. Know what's realistic before you scope the conversation.

Upfront

Guided Compliance Setup

The implementation engagement. Paid work, delivered by you, that gets the client structured from day one.

Recurring

Partner platform revenue

Ongoing revenue on the Cleverer subscription once the client's live.

Add-on

Policy Builder

A faster, smaller entry point for clients who want the policy layer sorted without the full setup.

Ongoing

Compliance reviews

Periodic review work, priced and delivered however suits your existing service model.

Remediation

Technical uplift

The gaps the process surfaces become your remediation work, on your terms.

Long term

A stronger relationship

You're operating above "the people who fix the laptop." That's what makes the rest of your services stickier.

The engagement

What the first client engagement actually looks like

Worked examples

Two ways this plays out

Illustrative only, not real clients.

Illustrative example

Financial services practice, eight staff

Insurance renewal is six weeks out. The questionnaire asks for a data handling policy, training records and an incident response process. Technical controls are partially in place. There's no documented policy, no training register, and three external platforms touching client data with no vendor register.

Trigger and gap

  • Cyber insurance renewal inside six weeks
  • No written privacy policy or training records
  • No vendor register despite three external data platforms

What happens

  • Exposure Audit run against the renewal deadline
  • Guided Compliance Setup plus Policy Builder before renewal
  • MSP tightens MFA on the client portal and reviews backup encryption
  • Recurring review timed to next year's renewal cycle
Illustrative example

Allied health clinic, expanding from one site to three

A near miss, a file almost sent to the wrong recipient, rattles the owner enough to ask their MSP a straight question. Nothing breached, but it's on their mind and they're growing fast.

Trigger and gap

  • Near-miss incident with patient data
  • No documented policies or role based training
  • No register tracking access across three sites

What happens

  • Readiness Check run first, no active deadline, real curiosity
  • Guided Compliance Setup builds registers across all three sites
  • Role based training rolled out to clinical and admin staff separately
  • Management review cadence set to catch the next one before it's real
Separate exercise

Client Opportunity Finder

Not connected to the scenario tool above. Use this to score a specific client from your own book, one at a time.

0 / 22
Lower priority
Tick what applies to see why.
Not a validated formula, a triage guide. One live trigger, a renewal in two weeks, an active incident, can outrank the score.

Do this before you pitch anyone

Takes an afternoon. Turns this from a page you read into a pipeline you're actually running.

  1. Open your client list. Top 10, by relationship strength or revenue, whichever list you'd actually call first.
  2. Score each one against the Client Opportunity Finder above. Be honest, don't inflate it to make the list look better.
  3. Mark the signals: regulated or privacy-heavy sector, sensitive data, insurance or tender pressure, known technical gaps, good security but weak evidence, already receptive to cyber, repeatedly deferred security work.
  4. Sort into three bands. You'll likely land two or three strong, four or five worth a conversation, a couple lower priority. Normal.
Pick the top three. Do not pitch your entire client base.

Ready to put this in front of a client?

Run the scenario tool above for your first call, then talk to us about the partnership itself.

General information only. This is not legal advice.

© 2026 Cleverer. Human-layer cyber compliance for Australian business.