Cyber attacks are increasing in frequency and impact. Last year, Marks and Spencer reported a data-related security incident that hit headlines. This month, Jaguar Land Rover and Heathrow Airport have also been associated with cyber disruption stories. Even the best-known brands are vulnerable. Your clients are reading the same news and wondering what it means for them.
As an MSP, your role is not only to respond when things go wrong. It is to educate, prepare, and help clients reduce risk before an incident occurs. Here is a practical framework you can use.
What Your Clients Need to Understand First
- No business is too small. Attackers automate. Size and sector are not protection.
- People are the first line of defence. Most incidents start with human error, such as a phish.
- Basic controls stop most issues. Multi factor authentication, patching, backups, and least privilege reduce the majority of risk.
- Response time matters. Clear steps in the first hour can limit damage and downtime.
Five Practical Ways to Educate Clients Now
- Run a quarterly awareness session
Host a plain-English 45 minute briefing for all staff. Cover current scams, recent UK incidents, and the one thing each person can do today. Record it for new starters. - Simulate phishing and coach, not punish
Send monthly phishing simulations and follow up with short coaching for anyone who clicks. Focus on learning. Share team scores and improvements to keep motivation high. - Publish a simple cyber hygiene checklist
Create a one page PDF your clients can print and use. Include: MFA on all accounts, software updates, password manager, restricted admin rights, tested backups, encrypted devices, device lock policies. - Share timely, non-alarmist updates
When a high-profile breach hits the news, publish a short client note. Explain what happened in general terms, what the likely vector was, and what you are doing or recommending. Close with one clear action, such as “enable MFA on all email accounts by Friday”. - Make incident response visible
Provide each client with a written, step-by-step incident response plan. Include who to call, what evidence to preserve, and how to communicate. Run a 30 minute tabletop drill twice a year.
Suggested Topics for Your Next 3 Client Communications
- “How MFA protects your email from account takeover”
- “Ransomware in plain English, how it starts and how to stop it”
- “Backups that actually restore, a quick test you can do this week”
How to Turn Education into Measurable Risk Reduction
- Baseline and track phishing simulation click rates each month.
- Audit MFA coverage across Microsoft 365, email, VPN, and critical apps.
- Track patch compliance by device group and set a weekly target.
- Test restore times quarterly and record the results.
- Report these metrics to client leadership in a simple monthly scorecard.
Objections You Will Hear, and How to Respond
- “We are too busy for training.”
Run 10 minute micro sessions at team meetings and share 2 minute videos by email. - “We do not handle sensitive data.”
Every business holds personal data and operational information. Disruption, fines, and reputational damage do not require secret IP. - “MFA annoys our users.”
App based prompts add seconds and block most account takeovers. It is the single highest return control.
Who This Approach Is Best For
- SMEs with Microsoft 365 or Google Workspace
- Distributed or hybrid teams
- Regulated sectors where audit trails matter
Want help launching a simple, effective client cyber education programme? Get in touch for a free outline plan and templates you can start using this week. We will tailor it to your client base and make it easy to run every month.