The Pulse Check - Quick Start Guide
This documentation may contain references to third party software or websites. N-able has no control over third party software or content and is not responsible for the availability, security, or operation, of any third-party software. If you decide to utilize a release involving third-party software, you do so entirely at your own risk and subject to the applicable third party’s terms and conditions of the use of such software. No information obtained by you from N-able or this documentation shall create any warranty for such software.
Download The Pulse Check resources and Documentation HERE
Business Resilience Pulse Check
PC-001 Program Guide
Everything you need to sell, deliver, and grow a Business Resilience Pulse Check practice.
Audience: MSP, MSSP, and vCISO practitioners
Version: 1.0
Date: July 2026
How to Use This Guide
This guide is organized so you can read it once to understand the program, then use it as a step-by-step reference for every engagement.
- Sections 1–3 explain what the Pulse Check is, who it serves, and what is in this package. Read these first.
- Section 4 covers the quality standards every engagement must meet. Read before your first engagement.
- Section 5 is the scenario selection guide. Use it when choosing which scenario to deliver.
- Section 6 is the operational walkthrough, the step-by-step process for running a complete engagement from first prospect conversation through annual renewal. Every document is referenced by its exact filename and folder. This is the section you will return to repeatedly.
- Section 7 explains how Pulse Check findings connect to your managed services stack, and the boundary rules that keep the exercise honest.
- Section 8 is the 90-day launch plan for getting from “I have the program” to “I’m delivering my first Pulse Check.”
- Section 9 is the business case for building a Pulse Check practice.
1. What the Pulse Check Is
The Business Resilience Pulse Check is a structured, scenario-driven tabletop exercise that measures a client organization’s ability to withstand, respond to, and recover from business disruption, evaluated through the lens of business impact, not technical configuration.
In a Pulse Check, a cross-functional leadership team walks through a realistic disruption scenario in a facilitated, 2–3 hour discussion. There is no technical testing. No systems are touched. The exercise tests what people would actually do: who makes the call, who gets notified, what plan gets pulled off the shelf, how the organization communicates, and where the process breaks down.
A dedicated observer documents every decision, gap, and strength. A peer-reviewed After-Action Report translates those observations into severity-rated findings with specific, actionable recommendations. The report becomes the client’s resilience roadmap.
1.1 What It Is Not
The Pulse Check is not a penetration test, vulnerability scan, security audit, compliance assessment, or technical configuration review.
It tests organizational decision-making, communication, and coordination under simulated pressure. Every client-facing document in this package makes this clear, and every proposal includes explicit scope exclusions.
1.2 Scope by Design
The Pulse Check produces a real After-Action Report, but a deliberately scope-limited one.
A single 2–3 hour exercise samples the organization’s resilience through one scenario lens. It does not evaluate the full breadth of the organization’s technology environment, administrative processes, and operational resilience, and the absence of a finding in an untested area is not evidence that no gap exists.
Quality Standard: The Scope Limitation Is a Feature
Every AAR states its own limits plainly. That honesty is what makes the findings credible, and what makes the Pulse Check a natural starting point for an organization’s resilience program rather than a false clean bill of health.
Never remove or soften the scope limitation language in the Pulse Check AAR Template.
1.3 The Advisory Relationship Model
The Pulse Check is designed to be the entry point into a recurring advisory relationship. It is the diagnostic that starts the relationship by answering the question: how prepared is this organization, really?
The progression is:
- The Pulse Check surfaces gaps.
- The After-Action Report documents them.
- Advisory conversations connect gaps to your capabilities.
- The client engages services based on evidence.
- The annual Pulse Check validates that investments are working.
The advisory relationship is built on trust. Trust is built by measuring honestly, reporting accurately, and letting the findings, not the sales process, drive the conversation about what comes next.
2. Who the Pulse Check Serves
2.1 The Client
The ideal client is an SMB or mid-market organization with 20–500 employees that:
- Has never conducted a tabletop exercise
- May or may not have documented response plans
- Faces regulatory requirements for testing
- Has cyber insurance or wants it
If they match your ideal client profile, they are a valid candidate.
The Pulse Check is deliberately broader than cybersecurity. It tests business resilience, the ability to continue operating through any disruption. This makes it accessible to non-technical decision-makers who might not engage with a “cybersecurity exercise” but will engage with “what happens if your comptroller has their laptop stolen.”
2.2 The Practitioner
The program is designed for MSPs, MSSPs, and vCISOs who want to:
- Add a high-margin advisory service
- Create a structured entry point for client relationships
- Generate demand for their managed services stack
- Provide compliance evidence clients need
- Build recurring revenue through annual cycles
You do not need to be a security expert to deliver the Pulse Check. The program provides everything: scenario packages, facilitation guides, observation tools, report templates, and quality controls.
What you need is a facilitator who can manage a room, ask good questions, and write clearly. There is no replacement for experience, soft skills, and practice.
3. What’s in This Package
This package contains 27 core documents and 12 scenario packages organized into 8 folders. Each folder corresponds to a stage in the engagement lifecycle.
The package is fully self-contained. Every document referenced anywhere in the package is in the package.
00, Quality Standards
| Filename | What It Does |
|---|---|
Severity and Finding Standards.docx | Defines the 5 severity levels, the four-part finding structure, the writing standards for findings, and the peer review standard. The calibration reference for every AAR. |
Sample Findings Library.docx | Worked examples of well-written findings at each severity level across the scenario types. Use as a quality benchmark when writing your AAR. |
01, Sell
| Filename | What It Does |
|---|---|
Service One-Pager.docx | One-page client-facing overview. Hand to the prospect at the first meeting or attach to your initial email. |
Sales Playbook.docx | Internal sales kit: slide-by-slide content for a 15-slide prospect presentation, 8 common prospect questions with tested answers, and 5 objection-handling frameworks. |
Proposal Template.docx | The document that closes the deal. Fixed-scope proposal with deliverables, timeline, investment, client responsibilities, and scope exclusions. |
02, Contract
| Filename | What It Does |
|---|---|
Mutual Non-Disclosure Agreement.docx | Bilateral NDA protecting both parties’ confidential information. Execute before exchanging any confidential information. |
Statement of Work and Engagement Terms.docx | Single engagement instrument: scope, deliverables, timeline, payment, advisory disclaimers, liability limits, privilege guidance, and the Cancellation and Rescheduling Policy as Exhibit A. |
Pre-Exercise Forms.docx | Form A: Client Authorization and Sign-Off, signed by the coordinator at least 5 business days before the exercise. Form B: Participant Confidentiality and Rules of Engagement, signed by every participant before the exercise begins. |
03, Plan
| Filename | What It Does |
|---|---|
Client Intake Packet.docx | Sent to the client at kickoff. Section A is the intake questionnaire whose answers drive scenario selection and customization. Section B is the documentation request list. |
Planning Workbook.docx | The facilitator’s working document for the 4–6 week planning cycle: timeline, SMART objectives, participant identification, stakeholder absence framework, logistics checklists, scenario customization checklist, and the participant invitation letter template. |
04, Scenario Packages
Complete, standalone, exercise-ready packages. Select one per engagement based on the client intake.
Each package contains:
- Scenario narrative with 3 modules and discussion questions
- Master Scenario Events List with 8–9 injects
- Simulated artifacts
- Facilitator notes with probe questions
- Customization checklist
- Regulatory disclaimer
See Section 5 for selection guidance.
05, Deliver
| Filename | What It Does |
|---|---|
Facilitator Guide.docx | Master delivery document: delivery model, business-impact facilitation techniques, run-of-show, agenda, hot wash, closing conversation script, and the real-incident-during-exercise protocol. |
Participant Guide.docx | Client-customizable handout for participants: exercise overview, ground rules, scenario background, and post-exercise expectations. |
Observer Kit.docx | Part 1: the observer’s role, the 7-category observation framework, ethics, and notes handling. Part 2: the structured note-taking template. |
Exercise Day Forms.docx | Sign-In Sheet for compliance evidence and Participant Feedback Form. |
06, Report
| Filename | What It Does |
|---|---|
Pulse Check AAR Template.docx | The primary deliverable: 11 mandatory sections plus appendices, including the scope limitation statement, four-part findings, findings matrix, remediation roadmap, and the Improvement Plan appendix. |
Executive Summary Template.docx | 1–2 page board-ready summary in business language. Standalone document for C-suite distribution. |
Compliance Evidence Package.docx | Assembly guide for audit-ready documentation, with framework-specific guidance for HIPAA, PCI-DSS, SOC 2, CMMC, and cyber insurance. |
Improvement Plan Tracker.xlsx | Working corrective-action tracker the client uses after delivery: one row per finding, owners, dates, status, and reference tables. |
Sample AAR - Infrastructure Outage.docx | Complete worked example of a finished AAR based on GS-2, Extended Infrastructure Outage, for a fictional 85-person property management company. Quality reference showing expected structure, tone, depth, and calibration. |
07, Operate and Renew
| Filename | What It Does |
|---|---|
Operations Manual.docx | End-to-end delivery workflow, engagement kickoff checklist, quality gates for all six phases, post-engagement closeout checklist, and the facilitator readiness and training path. |
Annual Renewal Proposal.docx | Next-cycle proposal template with maturity trajectory framing: a new Pulse Check scenario or an annual program. |
Facilitator Delivery Log.xlsx | Running record of every engagement with quality metrics, revenue tracking, and a practice dashboard. |
Facilitator Training Plan.docx | Skills-based training path for first-time facilitators. Progressive four-phase learning approach: read, watch, practice, deliver. No certification prerequisites. |
Observer Training Guide.docx | Teaches the observer role from scratch: selective attention, real-time note-taking, observation-to-data translation. Includes three practice exercises and a readiness checklist. |
Third-Party Impacts, Law and Liability.docx | Legal, insurance, and liability guidance for third-party exercise delivery. Covers insurance positioning, privilege considerations, discoverable evidence, vCISO dual-role risk, and engagement structure recommendations. |
4. Quality Standards
Five non-negotiable standards apply to every engagement. These are the minimum floor, not guidelines.
4.1 The Observer Mandate
A dedicated observer is required at every exercise. No exceptions.
The observer does not participate in the discussion. They observe, document, and collect data. The observer’s notes are the primary data source for the AAR.
No observer means no exercise.
4.2 Peer Review
Peer review strengthens every AAR.
When available, have a qualified person who was not involved in the exercise review the draft before delivery. The peer reviewer checks severity calibration, finding structure compliance, and writing standards.
If you are a solo practitioner starting out, using an AI tool to review your draft AAR against the quality standards in this package is a reasonable first step. It will catch structural issues, calibration inconsistencies, and writing standard violations.
AI review is a good start, but it is not a good finish. As your practice grows, build a reciprocal peer review relationship with another practitioner. Human reviewers catch judgment calls and contextual nuance that AI tools miss.
4.3 The Four-Part Finding Structure
Every finding in every AAR follows the same structure:
| Finding Part | Purpose |
|---|---|
| Observation | What was seen |
| Context and Risk Impact | Why it matters |
| Recommendation | What to do |
| Severity Rating and Framework Mapping | How significant it is and which compliance frameworks it connects to |
No exceptions.
See Severity and Finding Standards.docx in the 00, Quality Standards folder.
4.4 Severity Calibration
Every finding is rated:
- Critical
- High
- Medium
- Low
- Informational
Use the criteria in Severity and Finding Standards.docx.
Two facilitators rating the same finding should arrive at the same severity. When in doubt, rate conservatively and document the rationale. The peer reviewer can argue it down.
4.5 The Advisory Language Boundary
No client-facing document produced under this program uses urgency language, sales language, or product recommendations.
The AAR recommends actions, not products. Every recommendation must be traceable to a Pulse Check finding.
If the chain of findings → gap → capability → recommendation breaks, the recommendation isn’t earned.
5. Scenario Selection Guide
Select one scenario per engagement based on the client’s intake questionnaire responses, industry, and risk profile.
All 12 scenarios are in the 04, Scenario Packages folder.
| If the Client... | Use This Scenario | Filename |
|---|---|---|
| Is in healthcare with EHR/PHI | GS-1a Ransomware, Healthcare | GS-1a - Ransomware - Healthcare.docx |
| Is in financial services | GS-1b Ransomware, Financial | GS-1b - Ransomware - Financial Services.docx |
| Has never done a tabletop exercise, any industry | GS-1c Ransomware, General | GS-1c - Ransomware - General.docx |
| Relies on one location or facility | GS-2 Infrastructure Outage | GS-2 - Extended Infrastructure Outage.docx |
| Has thin succession or key person risk | GS-3 Key Person Loss | GS-3 - Key Person Loss.docx |
| Depends heavily on 1–2 vendors | GS-4 Supply Chain Failure | GS-4 - Supply Chain Failure.docx |
| Is in a disaster-prone area | GS-5 Natural Disaster | GS-5 - Natural Disaster.docx |
| Is in healthcare with access management concerns | GS-6a Data Breach, Healthcare | GS-6a - Data Breach - Healthcare.docx |
| Is in financial services with vendor data sharing | GS-6b Data Breach, Financial | GS-6b - Data Breach - Financial Services.docx |
| Has customer PII and multi-state presence | GS-6c Data Breach, General | GS-6c - Data Breach - General.docx |
| Has public visibility or social media exposure | GS-7 Reputation Crisis | GS-7 - Reputation Crisis.docx |
| Has essential on-premises functions | GS-8 Pandemic Disruption | GS-8 - Pandemic Disruption.docx |
Guidance: First Engagement Recommendation
If this is your first Pulse Check delivery, start with GS-1c, Ransomware, General, or GS-3, Key Person Loss.
Both are universally applicable, produce strong findings for any organization, and don’t require industry-specific regulatory knowledge.
Guidance: When No Scenario Fits Exactly
Not every client maps cleanly to the twelve scenarios in this package. If you review a client’s intake and none of the scenarios feel right, or if you want to build a scenario around specific risks unique to their environment, consider using an AI tool to draft a custom scenario.
Tools like N-able N-zo that have direct access to a client’s asset inventory, endpoint configurations, and environment topology can generate high-fidelity, realistic scenario content grounded in the client’s actual infrastructure.
Use the scenario structure from any existing package as your template: 3 modules, MSEL with injects, discussion questions, facilitator notes, and customization guidance.
Not having the experience to write a scenario from scratch is not a reason to skip the engagement. It is a reason to use the tools available to you.
6. The Operational Walkthrough
This section walks you through a complete engagement from first prospect conversation through annual renewal.
Read it once to understand the full lifecycle, then use it as a checklist. The Trigger at the start of each phase tells you what event starts it. The Gate at the end tells you what must be complete before you move on.
Phase 1: Sell
Trigger
You have identified a prospect or received an inquiry about resilience testing.
-
Prepare your materials, first time only. Open
Service One-Pager.docxin01, Selland replace all placeholders. This is your leave-behind. Build your slide deck from the Sales Playbook’s presentation spec using your brand template. -
Run the prospect conversation. Lead with the diagnostic positioning: “Before we recommend anything, we measure where you stand.” Use the one-pager as a leave-behind and the Sales Playbook’s FAQ and objection frameworks in conversation.
-
Send the proposal. Customize every bracketed field in
Proposal Template.docxin01, Sell. Review the Scope Exclusions section. Do not remove it.
Gate: Phase 1 Complete
The prospect has accepted the proposal. Do not begin any work until the Phase 2 contracts are executed.
Phase 2: Contract
Trigger
The prospect has accepted the proposal.
-
Complete first-time setup. Before your first engagement, have your attorney review and customize all three documents in
02, Contract. Complete every[CUSTOMIZE]and attorney-review item. Save your customized versions as your standard templates. -
Execute the NDA first.
Mutual Non-Disclosure Agreement.docxmust be signed before you exchange any confidential information, including the intake packet. -
Execute the Statement of Work and Engagement Terms. Customize scope, scenario category, pricing, and dates. Exhibit A, Cancellation and Rescheduling, is part of the document. Both parties should acknowledge it.
-
Collect the deposit per the SOW payment terms, typically 50% upon execution.
The Pre-Exercise Forms in 02, Contract are used later:
| Form | When It Is Used |
|---|---|
| Form A: Client Authorization and Sign-Off | End of planning |
| Form B: Participant Confidentiality and Rules of Engagement | Exercise day |
They live in the Contract folder because they are legal documents, but their operational moment is in Phases 3 and 4.
Gate: Phase 2 Complete
NDA and SOW fully executed. First payment received. You are authorized to begin work.
Phase 3: Plan
Trigger
Contracts are executed and the deposit is received. The 4–6 week planning cycle begins now.
-
Kick off, days 1–5. Complete the Engagement Kickoff Checklist in the Operations Manual in
07, Operate and Renew. Assign your observer and brief them with the Observer Kit in05, Deliver. Send the Client Intake Packet in03, Plan. Section A is due back in 10 business days. Section B is due back in 15. -
Populate the Planning Workbook. Use
Planning Workbook.docxin03, Plan. Set the milestone timeline in Section 1 and share key dates with the client coordinator. -
Select the scenario, week 2. Review the returned intake, especially operational dependencies, key person risks, vendor criticality, and scenario preferences. Choose the scenario using Section 5 of this guide.
-
Develop objectives, week 2. Use Planning Workbook Section 2 to draft 3–5 SMART objectives and agree them with the client coordinator.
-
Customize the scenario, weeks 2–4. Read the selected scenario package completely, then work through the customization checklist in Planning Workbook Section 6. Replace every
[CUSTOMIZE]tag. -
Confirm participants, week 3. Use Planning Workbook Section 3 to identify 8–15 cross-functional participants and classify each by tier. Send the invitation letter in the workbook appendix at least 10 business days before the exercise, with Pre-Exercise Forms Form B attached.
-
Complete logistics, week 4. Work through Planning Workbook Section 5 for the delivery format.
-
Get authorization, 5+ business days before. Send Pre-Exercise Forms Form A with the scenario summary. Do not deliver the exercise without this signed authorization.
-
Handle absences. If a confirmed participant cancels, apply the Key Stakeholder Absence Framework in Planning Workbook Section 4.
| Stakeholder Tier | Action |
|---|---|
| Tier 1 | Reschedule or use a qualified proxy |
| Tier 2 | Proceed with the limitation noted in the AAR |
| Tier 3 | Proceed normally |
Gate: Phase 3 Complete
Intake reviewed. Scenario selected and customized. Objectives agreed. Participants confirmed and invited. Logistics complete. Form A signed. Observer briefed.
Phase 4: Deliver
Trigger
It is exercise day. All planning is complete and authorization is signed.
-
Complete morning-of setup. Complete the Pre-Exercise and Day-Of quality gates in the Operations Manual. Arrive at least 30 minutes early. Print or stage the Participant Guide, Exercise Day Forms, and Form B copies.
-
Collect arrival materials. As participants arrive, collect sign-ins and signed Form B confidentiality agreements before the exercise begins.
-
Run the exercise. Use the Facilitator Guide: run-of-show, module injects, probe questions, hot wash, and the advisory closing script. The observer works from the Observer Kit throughout and never participates.
-
Follow the real incident protocol if needed. If a real incident occurs, follow the Real Incident During Exercise Protocol in the Facilitator Guide immediately.
-
Close the exercise. Distribute and collect feedback forms. Preview the AAR timeline: draft within 15 business days, final within 30.
-
Debrief within 2 hours. Hold the facilitator–observer debrief. Align on top findings and likely severities. The observer secures their notes.
Gate: Phase 4 Complete
Exercise delivered. Sign-in sheet, Form B agreements, and feedback forms collected. Observer notes secured. Debrief complete.
Phase 5: Report
Trigger
The exercise is complete. The 15-business-day clock for the draft AAR starts now.
-
Compile sources, days 1–3. Collect observer notes, facilitator notes, feedback forms, client documentation, and the exercise objectives.
-
Write the AAR, days 3–10. Use
Pulse Check AAR Template.docxin06, Report. Calibrate every finding against Severity and Finding Standards and the Sample Findings Library in00, Quality Standards. Keep the scope limitation statement intact. -
Prepare companions, days 8–12. Prepare the Executive Summary Template and the Improvement Plan appendix. Stage
Improvement Plan Tracker.xlsxfor handoff. -
Complete peer review, days 10–13. Peer review is strongly recommended. If a human peer reviewer is available, use them. If not, review the draft against the quality standards using an AI tool as a starting point. Address all feedback before delivery.
-
Deliver the draft package, day 15. Deliver the AAR, Executive Summary, and Findings Matrix. Request client comments within 15 business days and schedule the After-Action Meeting.
-
Finalize by day 30. Run the After-Action Meeting, confirm Improvement Plan owners and dates, incorporate feedback, assemble the Compliance Evidence Package, and deliver the final package. Collect the second payment per the SOW.
Gate: Phase 5 Complete
Final AAR and companions delivered and accepted. Improvement Plan has confirmed owners and dates. Second payment collected.
Phase 6: Close and Renew
Trigger
Final deliverables have been accepted by the client.
-
Close out within 10 business days. Complete the Post-Engagement Closeout section of the Operations Manual: deliverables confirmed, invoicing, data handling per the SOW, lessons learned, and the Facilitator Delivery Log updated.
-
Activate the advisory relationship. Schedule 30/60/90-day check-ins.
| Check-in | Focus |
|---|---|
| 30 days | Remediation progress and questions |
| 60 days | Immediate-tier actions complete? Where can you help? |
| 90 days | Progress review and introduction to the annual cycle |
- Propose the next cycle. Send the Annual Renewal Proposal in
07, Operate and Renew60–90 days after delivery, customized with the client’s results and remediation progress.
Gate: Phase 6 Complete
Engagement closed. Data handled. Check-ins scheduled. Renewal proposal sent. The relationship continues.
7. How Findings Connect to Your Stack
The Pulse Check is not a sales tool. It is a diagnostic whose findings create natural advisory conversations.
You never sell from the exercise floor. You never recommend a product during the AAR review. You let the findings do the work.
- During the exercise: When a participant reveals a gap, the facilitator asks follow-up questions, not product recommendations. For example: “Who would you call to find out? How long would it take to get an answer?”
- In the AAR: The observation becomes a finding with a severity rating and a recommendation for action, never a recommendation for a product.
- In the advisory conversation: After delivery, use the mapping below. For example: “The Pulse Check identified uncertainty about your backup architecture. We offer a backup assessment that would answer that question definitively. Would that be useful?”
Quality Standard: The Rule
Every recommendation must be traceable to a Pulse Check finding: Finding → Gap → Capability → Recommendation.
If the chain breaks at any point, the recommendation isn’t earned and shouldn’t be made.
Never reverse the flow. Never steer a scenario because you want to sell a specific stack component.
Common finding-to-capability mapping
This table is an internal reference. It never appears in client-facing documents.
| Common Pulse Check Finding | Managed Services Capability It Maps To |
|---|---|
| No offline or isolated backup | BDR solution, immutable backup architecture, backup monitoring |
| No incident response or forensics relationship | IR retainer coordination, incident response planning |
| No pre-approved communication plan | Crisis communication planning, incident playbooks |
| Single admin for critical systems | Privileged access management, MFA enforcement, access governance |
| No credential escrow or recovery | Password management, identity governance, emergency access procedures |
| Undocumented IT procedures | Documentation services, knowledge base, SOP development |
| No vendor security assessment | Vendor risk management, third-party assessment services |
| No data classification or mapping | Data discovery and classification, DLP |
| No escalation thresholds | Incident response playbooks, decision authority documentation |
| Insurance terms unknown | Insurance policy review, broker coordination |
| No security awareness program | Awareness training platform, phishing simulation |
8. Getting Started: The 90-Day Launch Plan
Weeks 1–2: Build Your Foundation
- Complete the Facilitator Training Plan in
07, Operate and Renew. If you want additional methodological depth, FEMA offers free self-paced courses, IS-120.c and IS-130, attraining.fema.govthat provide useful HSEEP context. - Read this Program Guide completely, then Severity and Finding Standards, the Sample Findings Library, and the Facilitator Guide.
- Have your attorney review all three documents in
02, Contractand save your customized standard templates. - Brand your sales materials: customize the Service One-Pager and build your presentation deck from the Sales Playbook.
Weeks 3–4: Dry Run
- Conduct an internal dry run on your own team using GS-1c, Ransomware, General, or GS-3, Key Person Loss.
- Designate a team member as observer.
- Run the full exercise.
- Write a practice AAR from the template and have someone review it against the quality standards.
This is also a genuine test of your own organization’s preparedness.
Weeks 5–8: First Client
- Identify your first client, ideally an existing client who trusts you and will give honest feedback.
- Present the Pulse Check and send the proposal.
- Consider a steep discount or free delivery. At this stage, the experience matters more than the revenue.
- Execute contracts and run the planning cycle, Phases 2–3 of the walkthrough.
Weeks 9–12: Deliver, Report, Renew
- Deliver your first Pulse Check, Phase 4.
- Write and deliver the AAR, with peer review if available, Phase 5.
- Close out, begin advisory check-ins, and send the renewal proposal, Phase 6.
Your practice is launched.
9. The Business Case
9.1 Direct Revenue
Each Pulse Check generates direct revenue from the exercise fee.
Pricing is practitioner-determined based on your cost basis and market positioning. Expect realistic margins of 30–40% in year one as the practice matures, improving substantially with repetition as planning and AAR-writing time falls.
9.2 Advisory Relationship Revenue
The Pulse Check surfaces gaps that map to your managed services stack.
Clients ask “how do we address these gaps?”, which changes the conversation from sales negotiation to problem-solving. Every subsequent engagement is earned by evidence.
9.3 Client Retention
A client whose resilience roadmap you manage has a stronger relationship than one who just buys managed services.
The Pulse Check creates shared language for resilience investment, a documented baseline, and an annual touchpoint that renews the relationship.
9.4 Competitive Differentiation
Most MSPs lead with products.
The practitioner who leads with “before we recommend anything, we measure” occupies a different position, one that is difficult to replicate because it requires methodology, quality standards, and the discipline not to sell from the exercise floor.
Guidance: Insurance Positioning
Many cyber insurance carriers view regular, documented resilience testing favorably during underwriting.
Never promise specific premium outcomes. Direct clients to their broker for carrier-specific impacts.