Industry

    MSP video: what your SOC does at 2am

    Vendor logo walls do not differentiate an MSP. A dashboard screen-capture explainer of your response process does, with two rules that keep it publishable.

    Versely Team9 min read

    Open three managed service provider websites in the same metro and you will find three versions of the same wall of vendor badges. Microsoft. A detection and response vendor. A backup vendor. A PSA and an RMM. The wall is a procurement fact, not a differentiator, and the prospect knows it — half the time your competitor resells the identical stack.

    What actually differs between MSPs is the process between the alert firing and a human calling the client. Response time, escalation path, who has authority to isolate a machine at two in the morning, what gets communicated and when. Buyers cannot see any of that in a proposal, which is exactly why it belongs on video.

    The format is unglamorous and it works: a dashboard screen capture, a voiceover, a running clock, one incident followed end to end.

    Build the video around a clock, not a capability list

    Structure the piece as a timeline. Every beat gets a timestamp on screen, because timestamps are what convert "we monitor 24/7" from a slogan into something a prospect can compare against their current provider.

    A workable eight-beat structure, four to six minutes:

    1. T+0 — the signal. What fired, on which endpoint, from which sensor. Show the actual alert card.
    2. T+minutes — triage. What the analyst checks first to decide real versus noise. This is the beat most MSPs skip and the beat that separates you from a reseller with a dashboard.
    3. The decision point. Contain now or investigate first, and who is allowed to make that call at that hour. Name the role and the authority level, not the person.
    4. Containment. Isolation, credential revocation, whatever your runbook says. Show the action being taken in the console.
    5. The client contact. Who gets called, on which number, and what they are told in the first sixty seconds. Read the actual script you use.
    6. Investigation. Scope, blast radius, what was touched. Keep it short — the buyer is not evaluating your forensics.
    7. Recovery and verification. How you confirm the environment is clean before you say so.
    8. The written record. The incident report the client receives, and when. Hold it on screen long enough to read the section headings.

    Cut each beat as a standalone short. Beat 3 alone — "who decides to isolate a machine at 2am, and how long that takes" — is the single most useful sixty seconds an MSP can put in a sales email, because the honest answer at most competitors is "we open a ticket and someone looks in the morning".

    Rule one: never a live client tenant

    The console footage comes from a purpose-built demo tenant. Not a redacted client tenant, not a client tenant with a screen-blur pass, not "we only showed the dashboard view".

    Two reasons, and the first is contractual before it is legal. Your MSA almost certainly carries a confidentiality clause covering client environment data, and hostnames, user names, IP ranges, ticket subjects and geolocation pins are environment data. Showing one client's console to prospects is a disclosure nobody gave you permission for — the kind that surfaces two years later when a prospect turns out to be that client's competitor.

    The second reason is that redaction on video fails in ways redaction on a screenshot does not. A blur on a tooltip does not follow the tooltip when it moves. A hostname appears for four frames during a page transition. An autocomplete dropdown drops a real email address in as you type. A toast fires from a different tenant mid-recording. You will not catch all of it, and one frame is enough for someone to freeze on.

    So build the demo tenant properly, once:

    • Fictional company, fictional domain, hostnames that follow your naming convention but belong to nobody.
    • Realistic volume. An empty console reads as a small MSP — seed enough noise that the queue looks like a real Tuesday.
    • The alert types you want to explain, staged so you can trigger them on demand for a re-record.
    • A browser profile with no other sessions, OS notifications off, clean bookmarks bar, no signed-in personal accounts.

    Record at native resolution and scale down in the edit rather than recording a scaled window — text stays legible and you keep the option to punch in. Security and data questions for AI content tools covers what to ask before console footage goes into any pipeline.

    Rule two: never a lapsed or aspirational attestation

    The second thing that gets an MSP into trouble on camera is a compliance claim that was true once, or was never quite true as stated.

    A SOC 2 Type II report is an attestation covering a defined observation period, issued after an examination by a CPA firm. There is no permanent certified state. "We are SOC 2 certified" is wrong twice over — wrong noun, no period attached. The publishable version names what happened and when: an examination completed, the trust services criteria in scope, and the period the report covers. When that period ends the video needs a decision, not a shrug.

    CMMC has the same shape and higher stakes, because the audience is a defence supply chain that can verify you. "CMMC compliant" says nothing on its own. The claim that means something names the level, names whether the assessment was a self-assessment or a third-party assessment, and carries a date. If you are working toward a level rather than holding one, the phrase is "working toward", said out loud, in the voiceover, not buried in a footer.

    Practical controls that make this survivable:

    Control What it looks like
    Date every claim in-frame "Report period ended [month, year]" as a typed overlay, not a caption
    One claims register Every compliance sentence in every video, with the document that backs it
    A review date per asset Diarised for the month a report period ends, with an owner
    Rebuild, don't patch Keep the timeline so the overlay can be re-typed and the video re-exported
    Kill switch If a claim lapses and the re-export slips, the video comes down that week

    That last row is the reason to build these on a re-renderable timeline rather than shipping a flat file to an agency. When the attestation date changes you re-type one overlay and export again — reusable editor drafts covers running the same layout across a library. Iterate on 480p previews, which are free and carry a short per-user cooldown, and pay once for the final export.

    The same discipline applies to anything you say about client outcomes. A downtime figure, a "zero breaches" line, a response-time average — each needs a source you could produce on request, and none of them should be a round number you remembered. Testimonials from named clients carry FTC endorsement disclosure obligations on top of everything above.

    Production notes that matter for console footage

    The material is dense and the viewing context is a laptop at work or a phone on a commute. Both want the same things.

    • Punch in. A full console view shrunk to fit a feed is unreadable. Scale to the region that matters for each beat; let the wide shot appear only at transitions.
    • Type every label. Never let a model render an alert name, a severity level or a timestamp. Overlay text goes on as timed text so it lands on the exact frame.
    • Burn the captions in. Half this audience watches muted in an open-plan office. Add captions and keep them plain — this is information, not a montage.
    • Voiceover over silence. A synthetic narrator reading a runbook is entirely appropriate here — add voiceover, skip the music bed, and hold the same voice across the library so assets recorded months apart still sound like one company.
    • Generate the connective tissue only. Title cards, sector context, an abstract network visual between chapters. Never a fabricated console, never a fabricated log line.

    For how much technical depth a non-technical buyer tolerates, explainer video production for complex B2B applies directly. If you sell a security product as well as a service, AI video for cybersecurity companies covers that half, which is a different job.

    Where the finished pieces go

    The long version lives on a page a salesperson can link to mid-cycle, not on the homepage. The homepage gets beat 3 as a sixty-second cut. The rest of the library fills predictable gaps:

    • Onboarding explainer. The first thirty days of a transition, week by week. Reduces the biggest objection to switching provider.
    • Co-managed model explainer. For prospects who already have internal IT and are afraid of being replaced.
    • One clip per service line. Backup verification, patch cadence, phishing simulation results. Each maps to a page and to a paid placement.

    FAQ

    Is a recorded incident from a real client ever usable with permission?

    Rarely worth it. Even with written permission you are publishing that a specific organisation had an incident, and they will regret that being public long before you regret using it. If a client genuinely wants to be a reference, put them on camera talking about how the response felt — no console, no environment detail, no incident specifics.

    Can we use a generated presenter instead of a staff analyst?

    For narration over console footage, yes, with disclosure. For anything that presents as your analyst describing what they personally did, no. A synthetic figure introduced as a member of your SOC is a fabricated credential, and it is the kind of thing a technical buyer will test by asking to meet them.

    How technical should this be?

    Technical enough to be checkable, plain enough for a finance director. The test: an IT manager recognises every screen as real, and a non-technical owner can repeat the escalation path back to you afterwards. If you find yourself explaining what an EDR agent is, put the definition in an overlay and keep the voiceover moving.

    What do we do when the attestation report period ends?

    Decide before it ends, not after. Either the re-examination is complete and you re-export with the new dates, or the claim comes out of the video entirely and the asset ships without it. The one option that is not available is leaving last year's date on a page you are actively driving traffic to.