If you’re a Service Provider to Compliant Customers that isn’t compliant with any security standards, you likely don’t realize the burden you’re forcing your clients to take on.
As a non-compliant Service Provider, your clients can’t use your certifications to support their compliance posture. Instead, they have to coordinate all of their evidence directly with you. To make matters worse for your Clients, you may be charging them additional fees to provision the evidence they need to support their audits. Even if you’re not charging your customers, then this time becomes a burden on your organization. Either way, someone is losing out in the grand scheme of things.
As a Service Provider, your non-compliance becomes a much bigger problem than you may realize for your customers: they’re forced to pay with their own man-hours managing/processing additional items on their own certification, and they also pay you to prove that you’re operating in a compliant manner. It also becomes your customers’ responsibility to provide ongoing oversight of you as their Service Provider, as part of their annual compliance cycle.
For some of your customers, it’s a baseline compliance pain that they get used to without realizing that the entire dynamic could be dramatically different. For others, they see the insanity of the situation (or worse yet your competition points this out to them) and find a compliant Assessed Service Provider at a lower overall cost. For your company, it means you run a strong risk of having unhappy customers coupled with a high turnover rate.
There are three major reasons Service Providers tell me they don’t venture into the compliance arena:
- They have no time
- Compliance is far too expensive
- There’s no compelling event to become compliant
Those are myths that are far from reality. The fact is, becoming compliant is good for business. It will reduce wasted time, help grow your business, and help protect you from catastrophic events. Here’s how.
So-So Security Is Simply Bad Business
Compliance Reduces Wasted (And Expensive) Hours
If you’re like most Service Providers, you’re chronically strapped for resources, which leads you to put off compliance because you can’t find the time or bandwidth to manage the project. But this approach fails to consider how much time you’re already wasting every day.
Whenever your clients have to answer security questionnaires or gather evidence for their own audits, those requests come to you as service tickets. Maybe it’s one ticket with many parts, maybe they come across as a series of individual tickets. These compliance requests get buried deep inside standard support channels right alongside fixing standard printer issues, deploying new servers, or applying day-by-day patches. And that drives support costs up, rendering your overall delivery mechanism less effective.
Take a simple, real-world example: a client needs a screenshot from a firewall showing that it has been patched with the latest firmware. For a firewall administrator to log into the system, grab the screenshot, name the file correctly, attach it to the ticket, and push it back to the customer, you’re looking at a 15-minute effort.
A 15-minute task doesn’t sound bad in the grand scheme of things, but there are other pieces of evidence that take hours to put together. If you multiply that simple 15-minute task across 12 different clients, your administrator has just burned three hours of time that you are never getting back.
When you expand this across an entire client base, you’re flushing scarce resource time straight down the toilet. If your organization blows 80 hours of compliance response time across 10 internal resources, that equals 20 weeks of work in a year. That is more than one-third of a man-year completely wasted on these support tickets.
Using the above example, let’s say that these resources could otherwise be billed at $150/hr – that means the opportunity cost of this decision cost your company $120k! How many dollars did your company waste last year on those kinds of tasks? You may not have a clue how much of your margins you’re bleeding.
Alternatively, becoming certified under a compliance standard reaps tremendous time-saving benefits. In particular, you will no longer have to burn your most expensive technical resources. You can establish a centralized function that’s managed by a lower-level technical or non-technical administrator whose only job is to distribute your pre-validated compliance paperwork directly to the clients.
This single document validates that specific compliance items have been verified by an independent third-party Assessor. Streamlining your operational workings frees up your bench of resources, allowing you to safely take on three to five more clients, increases the underlying stability of your company, and provides a dramatically better customer experience.
Don’t Sweat It! How to Master Your First Compliance Certification Project
Compliance Helps Grow Your Business
Service Providers frequently turn away from compliance because they assume the process will automatically cost them an arm and a leg. They look at the massive Assessment Firms in the industry and get immediately turned off by egregious upfront fees, licensing costs, and the aggregate expense of getting through an audit.
The reality is that if a Service Provider’s head and heart are in the right space and they care about protecting their company, their day-by-day operational practices are likely not that far off from best practice compliance rules. Your organization has viable choices.
You don’t have to select an astronomically challenging or unnecessarily costly standard. There are surprisingly affordable approaches to navigating a compliance assessment.
While launching a compliance program is undeniably an expense, the investment is highly worthwhile. Over the long term, a functioning compliance program conserves your internal personnel’s time, eases the burden on your customers, also it opens up major avenues to increase sales to both new and existing clients (upselling them on newly developed service lines as a direct result of your compliance activities).
Most importantly, because very few small to mid-sized Service Providers actually take the opportunity to become compliant, achieving it gives you a material and significant competitive advantage. You can use your compliance status as a strategic business benefit to customers that other providers can’t match.
Since the vast majority of operational teams don’t know the nuances of the security and compliance arena, you should leverage outside help. Bringing in a security and compliance Consultant will save your internal staff an astounding amount of wasted time trying to figure out all of the ins and outs on their own, while simultaneously holding the internal personnel accountable.
A Consultant can set you up for a successful Assessment, while potentially acting as an internal audit function, depending on your circumstances. Consultants can also provide direct guidance on hiring good Assessors that are great to work with, identify specific tools and vendors you can leverage, and bring higher-level documentation to the table. This ensures you select the exact compliance path that optimizes your dollar expenditure against actual business benefits.
Some of the best news is that a good Consultant can get you up and running without the need to take out a second business loan.
Ready to Get Serious About Compliance? Here’s How to Do It Right.
Compliance Protects You from Catastrophic Events
It is unusual for a small to mid-sized Service Provider to suddenly land a massive “whale” client that issues a mandatory thou-shalt-get-compliant edict. Because you’re so busy and you don’t feel that direct pressure from big customers, you’re not likely to connect the dots on the long-term benefits gained from taking a strong compliance posture.
Once an organization takes a strong stance toward security and compliance, the material business benefits naturally stack up. Becoming compliant:
- Frees up your internal headcount
- Mitigates the need to bring on additional headcount costs as you grow
- Accelerates your sales pipeline
- Drastically increases customer satisfaction
- Reinforces to your existing customers how seriously you take their protection
There is, however, an entirely different kind of compelling event to keep in mind. Service Providers are an incredibly juicy target for attackers, because they represent one-stop shopping. If a malicious actor can successfully breach a single Service Provider, they can pivot to hit an entire suite of underlying target organizations through this single attack.
Running a robust security and compliance program and validating your layers of protection through internal and external Assessments is a significantly better active protection mechanism than relying solely on your cyber insurance. It actively protects your organization, your clients, reinforces your internal network infrastructure, and provides a powerful mechanism you can bring directly to your customers to win a distinct sales advantage over other non-compliant Service Providers.
While cyber liability insurance will cover immediate financial costs, it won’t restore your reputation, bring your customers back, or undo the damage to your sales and marketing efforts that will last for years, if you even recover. It also won’t protect you from future attacks.
Becoming Compliant Makes Good Business Sense
Most SMBs go out of business within six months of discovering they’ve been breached. Not only will becoming compliant mitigate the possibility of complete business collapse, it will give you the opportunity to regain valuable time, grow your business, and sleep better at night.
If it’s time you started thinking about becoming a compliant Service Provider, TCT would be happy to answer your questions and provide you with options that fit your specific business — even if we aren’t part of the solution yet. If it means your business and your customers are protected, we’ve done our job.
Reach out today to start a conversation.

Get industry insider expertise delivered to your inbox
Subscribe to the TCT blog
