MSP Playbook

How MSPs Build and Sell a Device Security Service

juan@preyhq.com
Juan O.
Aug 3, 2026
0 minute read
How MSPs Build and Sell a Device Security Service

The email lands again. A client asks whether you can "handle the security on their laptops." You already manage their devices, so you say yes. Then you sit down to quote it and hit the wall: you have tools, not an offering.

Most MSPs are in exactly this spot. You run an MDM, you can push a remote wipe, you keep a device inventory somewhere. But none of that is packaged into something a client can read on a proposal, understand, and approve. The capability lives inside your stack. The service doesn't exist yet.

So one of two things happens. Either you fold device security into your flat managed-IT fee and give away margin on work that carries real liability, or the client buys it somewhere else and you lose the most defensible line item in the account. Both come from the same gap: you have device security as a function, not as a product.

This guide is about closing that gap. Not which tool to buy (you've probably already picked one from the best MDM platforms for MSPs), but how to turn the tools you run into MSP device security services you can package, price, pitch, and deliver across every client fleet without hiring a person to run it.

TL;DR

Turning device security into a service you can sell

  • From tool to offering: Managed device security means owning the outcome (find, lock, wipe, prove, report) across a client fleet, not handing over an MDM login.
  • You already have the tools: What's missing is the package: tiers a client can buy, a per-device price, and a pitch.
  • Tier it: Split it into Essential, Managed, and Complete so a dental practice and a law firm don't pay the same for different risk.
  • Price for margin: Charge per device per month, mark the license up two to four times, and keep no per-seat minimum so small clients stay profitable.
  • Sell the incident: Lead the pitch with what happens the day a device goes missing, and deliver from one console so onboarding a client is an afternoon, not a week.

What "managed device security" actually means for an MSP

A managed device security service is a recurring, per-device offering where you take responsibility for locating, protecting, and reporting on every endpoint in a client's fleet, from one console. It bundles the tooling, setup, incident response, and compliance evidence into a single line item, instead of handing the client a raw license.

That distinction is the whole game. Reselling a license means you give the client access to a dashboard and mark up the seat. Owning the outcome means that when a device goes missing, you're the one who finds it, locks it, and produces the report for their records. The client doesn't want another login. They want to stop thinking about the problem, and they want someone to call when it happens.

Think about how these incidents actually surface. A client's office manager finds out a laptop is gone only when the employee mentions it three days later, in passing. By then the "service" a license-reseller offers is a dashboard nobody logged into. The service a real provider offers is a check-in history showing where the device last appeared, a lock already pushed, and a wipe queued for the next time it connects. Same tool underneath. Completely different product.

That's why the framing matters before anything else. You are not selling software. You are selling the guarantee that a client's device problems become your operational responsibility, with proof to show for it.

What are your clients actually buying?

They are buying outcomes, not features, and every outcome maps to a capability you already run: find a lost device, lock or wipe it fast, prove it was encrypted, know what's in the fleet, and show an auditor. The job is translating each into a sentence a non-technical client understands.

  • "We can find it." Always-on device location plus check-in history, so a lost device isn't a mystery.
  • "We can lock or wipe it in minutes." Remote lock, remote wipe, and full factory reset, so exposure ends fast.
  • "We can prove it was encrypted." Encryption status (BitLocker) visible and exportable, so a lost laptop isn't automatically a reportable breach.
  • "We know exactly what they have." Hardware and software inventory, so the client stops guessing at their own fleet.
  • "We can show an auditor." Reporting the client can hand to a regulator or their own customer.

There's a sixth outcome worth calling out separately because clients will ask about it: privacy. Their staff will want to know if you're watching them all day. The honest, sellable answer is that tracking runs only when a device is declared lost or stolen, with role-based access to who sees what. Across 57 G2 reviews (a 4.7/5 average as of 2026), MSP reviewers keep returning to two things: the multi-tenant portal and remote reset. Hamza C., an MSP, put the privacy piece plainly: the portal lets his team "manage separate customer accounts with ease," and "for further privacy for the user, the system allows us to only track devices at the time when declared lost or stolen." That privacy story is part of what you're selling, not a footnote.

The capability that consistently surprises clients is remote full reset. As one IT consultant, Mel A., described it: "the ability to factory reset a Windows PC... I have never been able to initiate the process for a client remotely before finding Prey." When you're building the offering, that's the kind of concrete deliverable that makes a proposal feel real instead of generic. If a device is stolen, the workflow to locate, lock, and recover it is the outcome the client is actually paying for.

How to package device security into tiers clients can buy

Here's the mistake almost every MSP makes first: they sell "device security" as one undifferentiated add-on. Then they can never explain why the dental practice with six laptops and the law firm with sensitive client files pay the same rate for different risk. Tiers fix that.

Three tiers cover nearly every client. Keep each one describable in a single sentence.

Tier What's included Best-fit client
Essential Device inventory, always-on location, remote lock and wipe Small clients who need basic loss and theft protection
Managed Everything in Essential, plus encryption enforcement and reporting, compliance-ready exports, geofence and loaner alerts Regulated clients, or anyone who faces audits
Complete Everything in Managed, plus dark web credential monitoring and a priority incident-response SLA Clients with compliance mandates or high-value data

Two rules make tiers work. First, put at least one capability only in the top tier so there's a concrete reason to upgrade; dark web monitoring for MSPs is a natural anchor for Complete because it's easy to explain and hard to DIY. Second, white-label it. The reports the client sees should carry your brand, not your vendor's. You're the security provider; the tool is your back office.

Quick win: Draft your three tiers this week. Pick the one capability that lives only in the top tier, and write the one-sentence description of each tier that a non-technical client could read and understand. If you can't explain a tier in a sentence, the client can't buy it.

How to price a device security service for margin

Most MSPs price managed device security per device per month, marking the license up two to four times to cover setup, monitoring, and incident response. A flat per-device rate with no per-seat minimum lets you onboard a 15-device client as profitably as a 500-device one, anchored to the cost of one lost laptop rather than a subscription line.

Your real cost is not the license. It's the license plus the hour of onboarding, plus ongoing monitoring, plus the amortized cost of the incident you're promising to handle. Price off that loaded number, not the sticker price of the tool. When you mark up two to four times, you're not padding; you're covering the work the client is actually offloading onto you.

The no-minimum-seat point matters more than it sounds. Plenty of MSPs quote a 20-device client, discover their tool carries a 50-seat minimum, and watch the deal go underwater before they've added a dollar of margin. Small clients are where MSPs win on responsiveness, so don't let a licensing floor price you out of them.

And never lead with the license cost. Lead with cost-of-loss. One lost laptop with client data on it (replacement, the exposure, the client's own notification obligations) costs more than a year of the service. That's the sentence that closes the pricing conversation, and it's the one your champion repeats to their boss when they're the one who has to justify outsourcing to an MSP in the first place.

Quick win: Calculate your loaded per-device cost (license plus the setup hour plus monitoring), set a floor price you won't go under, and write the one-line ROI sentence for the proposal: "One lost laptop costs more than a year of this service."

How to pitch it: lead with the incident, not the feature list

Nobody buys a device security service off a feature matrix. They buy it because you made them picture the day it goes wrong. So open the pitch there.

Picture a 60-person law firm. A partner leaves a laptop in an airport lounge, client files on it. The MSP that sells managed device security locates the device, pushes a lock, and has a timestamped report in the client's incident log by that afternoon. The MSP that "set up an MDM once, two years ago" is on the phone explaining why nobody can actually see where the device is. One of those relationships renews without a single conversation about price. The other one starts shopping.

That's the pitch. Not "we offer geofencing and remote wipe," but "here's what happens the day a device goes missing, and here's the proof we'll hand you afterward." Then connect it to the client's own obligations: the compliance frameworks their customers and regulators impose require evidence of controls, and device-level reporting is exactly the evidence most clients can't produce on their own.

What does the client actually remember?

Not the feature list. They remember the day something went wrong and you handled it. Keep the written pitch to three things the champion can forward up the chain: what the service is, what it costs at their fleet size, and the three problems it solves. That forwardable version is what gets budget approved, because the person who signs rarely sat in your demo.

How to deliver it at scale without adding headcount

The service is only profitable if onboarding a new client is an afternoon, not a week. That's the whole operational test. If every client is a manual build, you've sold yourself a second job instead of a product.

How do you onboard a client without a site visit?

You template it. A new 40-device client should be a clone, not a build: push the agent silently across the fleet, add the client as a tenant in the console you already run, and copy a default policy set from your standard template. No per-device enrollment by hand, no trip to their office. The MSPs who scale this treat the first client's setup as the blueprint for every client after.

This is where the tooling underneath the service earns its place. Platforms built for multiple client environments give you one multi-tenant console, silent deployment, and per-client separation, which is the difference between a service that scales and one that eats your team's week. Prey's MSP portal is one example: a verified MSP reviewer described the dashboard as making it "very easy to deploy for multiple customers. Managing each client is a breeze," and another, Tara N., noted it "makes it easy to add (and remove) computers, tablets, mobile devices" per client, with the ability to "wipe clean in emergency situations. Peace of mind for everyone." The operational shape is what matters: add a client, clone a policy, deploy silently, respond from one place.

The response speed is the part clients actually feel. In one recovery, an MSP's client had an employee who claimed he'd returned his laptop. The device checked in, timestamped photos showed him using it at home, and it was back within the hour. That outcome (located, documented, recovered) is what the client is buying, and it only works if the tool responds in minutes. When a device is online, the wipe should start in seconds rather than waiting on its next scheduled check-in. When you set your SLA, that speed is the number you put in the proposal. If you're deciding what tooling sits under the service, the difference between an MDM and an RMM shapes what you can promise.

Quick win: Template your default policy set so a new client is a clone, turn on silent deployment, and define your incident-response SLA as a number you'll commit to in writing: "device located and locked within X minutes of a report."

Bringing it together

The MSPs winning device-security revenue aren't the ones with the best tool in their stack. They're the ones who turned the tool into an offering: three tiers a client can read, a per-device price anchored to the cost of a lost laptop, a pitch that opens with the incident instead of the feature list, and a delivery model that's a clone, not a build. The capability was always there. The service is what you construct on top of it.

So start where it's easiest. Write your three tiers and the one-sentence description of each. That single document is the difference between "we can do security" and "here's what you're buying, and here's what it costs." Everything else, the pricing math, the pitch, the onboarding template, is execution once the offering exists on paper.

What is a managed device security service?

It's a recurring, per-device offering where an MSP takes responsibility for locating, protecting, and reporting on the endpoints in a client's fleet from one console. It bundles the tooling, setup, incident response, and compliance evidence into a single line item, rather than reselling the client a raw MDM license they have to operate themselves.

How do MSPs price device security services for clients?

Most price per device per month, marking the underlying license up two to four times to cover onboarding, monitoring, and incident response. Keeping no per-seat minimum lets small clients stay profitable, and anchoring the price to the cost of one lost laptop (rather than to the license cost) makes the value obvious in the proposal.

Can MSPs white-label device security for their clients?

Yes. Multi-tenant platforms built for MSPs let you manage separate client accounts and present reports under your own brand, so you appear as the security provider and the underlying tool stays your back office. White-labeling is what turns a resold license into a service that belongs to you.

How is offering device security as a service different from reselling an MDM?

Reselling an MDM hands the client a login and an invoice; they operate it. Offering it as a service means you own the outcome: when a device goes missing, you find it, lock it, wipe it, and produce the evidence. The client buys a result and someone to call, not software to run.

How do MSPs manage device security across many client fleets?

From a single multi-tenant console that keeps each client's devices, policies, and reports separated. New clients are onboarded by cloning a default policy template and deploying the agent silently, so adding a fleet takes an afternoon instead of a manual per-device build. That operational model is what makes the service scale without new headcount.

Do you need a full MDM to offer a device security service?

No. A focused device security and recovery layer (location, remote lock and wipe, encryption visibility, inventory, reporting) covers the core outcomes clients ask for, and it can complement an MDM you or the client already runs rather than replacing it. Many MSPs layer it on top of an existing management stack to fill the tracking and recovery gap.

Run device security for every client from one console. Prey gives MSPs a multi-tenant portal to deploy, track, and recover devices across separate client accounts (Windows, macOS, Linux, Android, iOS, Chromebook) without adding headcount. Get started with Prey.