Marketing for managed IT providers and cybersecurity firms
You sell independent verification for a living, and most of your sector cannot be independently verified. This page is about the two free public registers that fix that, and about the one government statistic that will end any pitch built on fear.
FINDING
92% of 120 UK independent business websites across 10 sectors have no AI crawler policy of any kind, only about 6% use correct business-type structured data, and just 1 site in 120 has a hand-written llms.txt, according to Whito’s audit on 2 July 2026.
Source: AI readiness of UK business websites, Whito Research.
What we know, and what we have not measured yet
Whito has not run an AI visibility study on MSPs. The figures above come from a cross-industry technical audit in July 2026 and from DSIT, ICO, NCSC and IASME sources read at source on 8 September 2026.
Two things we could not establish. There is no official count of UK managed service providers; ONS’s 188,000 information and communication businesses is far broader and must not be presented as an MSP count. And we could not confirm the current parliamentary stage of the Cyber Security and Resilience Bill, because the Commons Library briefing we opened was last updated 8 July 2026.
The study worth running here is the one your own sector should have run: of the MSPs an AI engine recommends in a given city, how many appear on the ICO register and how many hold a current Cyber Essentials certificate. Both are free public checks. That runs later and lands on this page first, and the AI Visibility Index shows the method in the meantime.
Whito need-to-know for MSPs and cyber firms
- There is a statutory register, and it is the best free check in your sector. ICO registration and the data protection fee are statutory under the Data Protection (Charges and Information) Regulations 2018. The register is public and searchable by reference, organisation name or postcode, and a full list of fee payers can be downloaded. Anyone can verify in seconds whether an IT provider has met its own basic data protection obligation. Very few MSPs point at it.
- The fee is small and the penalty for missing it is not proportionate. Tier 1 micro is £52 for turnover up to £632,000 or no more than 10 staff, tier 2 is £78 up to £36m or 250 staff, tier 3 is £3,763. There is a £5 direct debit discount. Fixed penalties for non-payment under section 155 of the Data Protection Act 2018 are £400, £600 and £4,000, with a statutory maximum of £4,350. A £52 fee with a £400 penalty is a compliance point worth making to your own clients.
- Cyber Essentials prices are published in full. £320 plus VAT for 0 to 9 employees, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 plus. Cyber Essentials Plus is not published, being priced by network size and complexity. Organisations under £20m turnover achieving full certification get free cyber liability insurance. IASME is the NCSC’s official delivery partner with over 400 certification bodies.
- The certificate search has a twelve month window, which is a selling point. IASME’s public search covers certificates issued in the last 12 months, and states it must not be used for marketing or data research. So a lapsed certificate simply disappears. Being currently listed is therefore a live signal, not a historic one, and telling clients how to check is genuinely useful.
- The market is nearly all micro firms selling to micro firms. 2,603 active UK cyber security firms with £14.7bn revenue and about 69,600 FTEs, of which 58% are micro at 1 to 9 employees and 77% have under 50 staff. On the demand side, 44% of micro businesses use an external cyber security provider. Your buyer looks a great deal like you.
- The breach statistic everyone quotes has a second half. 43% of UK businesses identified a breach or attack in the last 12 months. The median cost of the most disruptive breach was £0, with the middle 50% ranging from £0 to £200 and the 95th percentile at £4,000 for smaller businesses. Any pitch built on catastrophe will meet that figure eventually. Build on something else.
Why MSPs struggle to sell what they are actually good at
Selling fear against a £0 median
The government’s own survey puts the median cost of the most disruptive breach at zero, with the middle half between zero and £200. A sceptical finance director who has read that will dismantle a fear-led pitch in one sentence.
Unverifiable in a sector that sells verification
Most MSPs publish no ICO registration number, no Cyber Essentials certificate reference and no ISO certification body. In a category whose whole proposition is independent assurance, that is a strange gap.
Priced against a floor nobody agrees on
Three UK publishers give per-user managed IT floors of £25 to £30, £40, and £40. Buyers arrive with the lowest and compare it to a fully managed price, which is a different product.
What actually works
In this order. Structure before scale.
Publish your own compliance evidence
ICO registration number, Cyber Essentials or Plus certificate, ISO certification body and certificate number, with links to the free public checks. If you sell assurance, be the most checkable firm in your town.
Teach the two free checks
A page showing a buyer how to search the ICO register and the IASME certificate search costs you nothing, is genuinely useful, and quietly raises a standard your less rigorous competitors will fail.
Publish tiered pricing with contents
Basic, standard and fully managed, with what each includes, per user per month excluding VAT. The published UK ranges are £25 to £150, so an unqualified number means nothing.
Sell response time, not catastrophe
Published response and resolution targets by severity, with last quarter’s actual performance. That is the thing a buyer can hold you to and the thing your competitors will not publish.
Write the compliance page for the client’s own obligations
Their ICO fee, their Cyber Essentials position, what their insurer asks for. You are selling into a market where 5% of businesses hold Cyber Essentials. That is the opportunity, not the objection.
Fix your own site’s machine readability
92% of independent UK business websites have no AI crawler policy and about 6% use correct business-type structured data. An IT provider whose own site fails that is not going to be recommended by an engine that cannot read it.
Quick wins this week
Publish your ICO registration number
With a link to the public register search. Free, two minutes, and it is the only statutory check in your sector.
Link the IASME certificate search
Free, public, and limited to certificates issued in the last twelve months, which makes a current listing a live signal rather than a historic claim.
Publish response targets and last quarter’s actuals
Two tables, no cost, and it moves the conversation from fear to performance where you can actually win.
Common mistakes
Building the pitch on breach catastrophe
The government’s own survey puts the median cost of the most disruptive breach at £0 and the 95th percentile at £4,000 for smaller businesses. That figure will turn up in the room eventually.
Claiming ISO without naming the certification body
UKAS accredits certification bodies rather than companies and publishes a free searchable list. Naming your body and certificate number is the difference between a claim and a fact.
Quoting the Cyber Essentials price as the whole cost
£320 plus VAT is the certification. Cyber Essentials Plus is a technical audit priced by network size and is not published. Quoting the first as if it covered the second creates a conversation you will lose later.
Managed IT and cybersecurity marketing guides
The statutory ICO register, the Cyber Essentials certificate search, and why a twelve month window makes a current listing worth more.
The published per-user prices disagreeThree UK publishers, floors from £25 to £40, and pen test day rates where one publisher’s floor sits above another’s ceiling.
Start, Build, Scale for an MSPWhich stage you are at, what a two-person provider fixes first, and what changes when the Cyber Security and Resilience Bill lands.
MSP tooling, and who publishes in poundsOne vendor publishing a clean GBP rate, two publishing dollars only, and one that will not publish at all.
The register that matters
One statutory register, one free certificate search, and regulation on the way.
Managed service providers face no MSP-specific UK regulation today, on the evidence we opened. What binds you are the general obligations, and the first is more useful as marketing than most MSPs realise. ICO registration and the data protection fee are statutory under the Data Protection (Charges and Information) Regulations 2018: tier 1 micro at £52 for turnover up to £632,000 or no more than 10 staff, tier 2 at £78 up to £36m or 250 staff, tier 3 at £3,763, with a £5 direct debit discount. Fixed penalties for failing to pay, issued under section 155 of the Data Protection Act 2018, are £400, £600 and £4,000, with a statutory maximum of £4,350 where a controller fails to provide enough information to determine the right fee. The register is public and searchable by registration reference, organisation name or postcode. Second, Cyber Essentials, run by IASME as the NCSC’s official delivery partner through over 400 certification bodies: £320 plus VAT for 0 to 9 employees, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 plus, with Cyber Essentials Plus priced by network size and not published. 37,298 Cyber Essentials certificates and 11,950 Plus certificates were issued between 1 April 2024 and 31 March 2025. The public certificate search covers the last 12 months only and explicitly forbids use for marketing or data research, which is worth respecting. Third, and coming: the Cyber Security and Resilience (Network and Information Systems) Bill, introduced on 12 November 2025, expands the regulations to include managed service providers, defined as organisations providing third-party IT services to other businesses. We could not confirm its current stage. All read at source on 8 September 2026.
Ready to win better clients?
See what search and AI engines can read on your site. Seventeen checks, scored out of 100, every result shown on the page, no email needed. Then list your business free in the Whito directory. Money cannot buy either.
Looking for an IT provider instead?
Whito is a marketing guide for the trade, not a booking site. If you are trying to hire, the Whito directory lists verified UK businesses, and every listing is checked against the public record before it appears.
Whito is independent and companies cannot pay to appear in our guidance. This page is marketing advice, not legal, data protection or security advice: check registration and fee obligations with the ICO, certification requirements with IASME and the NCSC, and any forthcoming duties with the relevant department.
