From sign-up to fully protected: how enhanced.io onboards new MSP partners in 30 to 45 days

From sign-up to fully protected: how enhanced.io onboards new MSP partners in 30 to 45 days

About Author

Hannah Lloyd

Hannah Lloyd is CRO and co-founder of enhanced.io. She leads global new business generation and works directly with MSP partners to build and sell security practices.

enhanced.io, the channel-only Open XDR SOCaaS for MSPs

One of the first things MSPs ask me when they're weighing up a new security platform is some version of the same question: this all sounds great, but how long before we're up and running? It's a fair question, and I don't think enough vendors answer it honestly. Most of the MSPs I talk to have been burned before by a vendor who promised a smooth deployment and then left them drowning in configuration work, undocumented APIs and a support queue that moved slower than a SIEM alert at 2am. 

So here is the honest answer, and I mean the whole thing rather than the marketing version. enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Onboarding a new partner onto that platform typically takes 30 to 45 days from kickoff to steady-state delivery, scoped to what is being onboarded. That figure is an average, and I'd treat it as indicative rather than a promise, because some onboardings run faster than that and where you land depends on site configuration, the size of the environment and how quickly your team gets us the information we ask for. I would rather tell you that up front than give you a single number that only holds in ideal conditions. You complete the onboarding forms and we do the heavy lifting alongside you, through the six phases below, in the order they happen. 

Phase 1: kickoff and service alignment 

The first thing that happens once you're on board is a kickoff call with your key stakeholders and your dedicated Fractional Security Director, or FSD. This is not a generic onboarding webinar, and I always tell partners not to expect a slide deck marathon. It's a working session built around your specific scope, objectives and delivery approach, and it happens before a single sensor gets deployed. 

Your FSD is a named, CISSP-certified security professional who sits between the enhanced.io SOC, your MSP team and your end clients. They're with you from day one, not handed over once some anonymous setup team has finished the technical work, and in my experience that continuity is what partners end up valuing most six months in. 

What gets covered in kickoff 

  • Scope definition: which client environments are being brought under monitoring 

  • Delivery model: whether you're running full 24/7 SOC support, platform-only or a blended approach 

  • Escalation paths: who gets called, when and how 

  • Success criteria: what "done" looks like at go-live 


Getting this alignment locked in early is what makes everything downstream move faster. When scope is clear, configuration moves faster, and when escalation paths are agreed up front, response is cleaner. It sounds obvious when I put it like that, but most onboarding failures I've seen start right here, with assumptions nobody bothered to write down. 

Phase 2: information gathering 

Before effective monitoring is possible, we need to understand what we're protecting. This phase is largely a documentation exercise, and we keep it lean with structured onboarding forms rather than asking your team to fill out a 40-page questionnaire. The reason I mention that is this is the phase where the timeline is most in your hands, because how quickly these forms come back is the biggest single driver of where you land in the 30 to 45 day range. 

What we gather: 

  • Critical assets: servers, endpoints, cloud workloads, OT/IoT devices and any BMS environments in scope 

  • Data sources: which tools and platforms are already generating logs and telemetry 

  • Access requirements: credentials, API keys and network access needed to connect the platform 

  • Escalation contacts: who on your team needs to be looped in for different alert severities 

Worth noting: enhanced.io integrates with over 400 security and IT tools, so in most cases your existing stack connects without any rip-and-replace. We work around what you already have, not the other way round. 

Phase 3: system configuration 

With the information gathered, we configure the platform to match your environment. This covers the Open XDR platform itself, network sensors and vulnerability scanning, all set up around your specific setup and goals rather than a generic template. 

What we configure 

  • The Open XDR platform: data ingestion pipelines, correlation rules and detection logic tuned to your client environments 

  • Network sensors: deployed to capture east-west and north-south traffic across physical, virtual and cloud infrastructure 

  • Vulnerability scanning: configured against your in-scope assets, ready to produce the monthly remediation reports your clients will see 

Agents deploy through your own tooling, so your engineers are not learning a new deployment method to get started. Some environments need a firewall reconfiguration, and a site with no virtualization needs a physical sensor, and both of those add time. 

This is where the depth of enhanced.io's visibility starts to become obvious. Most endpoint-only solutions miss the lateral movement happening between devices on the same network, and by deploying network sensors alongside your existing EDR, we cover the attack surface that agents do not see. Your EDR keeps doing what it does best and our sensors cover everything else, working alongside it rather than competing for the same job. 

Phase 4: system integration 

Configuration sets the platform up and integration connects it to everything else. In this phase we bring in your security tools and platforms, apply the required security controls and set the access policies that govern how data flows between systems. 

This is also where your existing stack gets properly wired in, whether that is Microsoft 365, Google Workspace, Okta, AWS, Azure or some combination of all of them. The platform correlates signals across identity, SaaS, cloud, network and endpoint into a single view, so your SOC analysts are not switching between six dashboards to work out what is happening in a client environment. 

For MSPs with clients in regulated industries, this phase also covers mapping your data sources to the relevant compliance frameworks. enhanced.io supports CMMC, NIS2, DORA, HIPAA, ISO 27001, NIST CSF and Essential Eight, so the reporting your clients need is built into the platform rather than bolted on afterward. 

Phase 5: hardening and tuning 

This is the phase that separates a well-deployed security platform from one that generates noise. Once the integrations are live and data is flowing, we run baseline hardening and alert tuning aligned to recognized security frameworks and best practice, and we do it before go-live rather than after. 

In practical terms, that means: 

  • Reducing false positives so your team is not chasing phantom alerts 

  • Calibrating detection thresholds to match the risk profile of each client environment 

  • Validating that escalation paths work as expected before you are in a live incident 

  • Confirming that compliance reporting maps correctly to the frameworks your clients need 

By the end of this phase the SOC team knows your environment, the alerts are meaningful and your FSD has a clear picture of your clients' security posture. What I've seen is that this is the phase that lets a partner put the service in front of a client with confidence on the day they go live, and tuning then carries on in steady state as client environments change. 

Phase 6: steady-state service delivery 

Once hardening is complete, you move into steady-state delivery. This is where the 24/7 SOC takes over as the operational backbone, and the relationship shifts from getting set up to running well and improving continuously. 

What steady state looks like in practice 

  • 24/7 SOC monitoring and response: the enhanced.io SOC is watching your client environments around the clock, with automated triage cutting through the noise and expert analysts handling what matters 

  • Monthly risk management meetings: your FSD leads regular reviews of security posture, outstanding vulnerabilities and any changes to client environments 

  • Automated threat assessment reports: delivered in the first week of every month, covering the Open XDR platform's findings alongside vulnerability remediation priorities, so you have something concrete to show clients 

  • Continuous tuning: the platform does not stay static, and as your client environments evolve, the detection logic evolves with them 

For MSPs, this is the part that changes the business model. Instead of reactive firefighting, you are delivering a proactive, documented security service with monthly reporting your clients see and understand, and that is what justifies the margin and makes the contracts sticky. 

Once you are a partner, you get the full onboarding timeline and the supporting documentation that sits behind it, including the RACI matrix, statements of work and sample threat assessment reports, so nothing here is a surprise once you are underway. 

The short version 

Onboarding typically runs 30 to 45 days across 6 phases, with a named CISSP-certified FSD alongside you from day one, no rip-and-replace of your existing tools and no building a SOC from scratch. As I said, that range is an indicative average, and a smaller or simpler environment with information supplied quickly will run faster than that. Here is the full sequence at a glance. 

Phase 

Focus 

1. Kickoff 

Scope, delivery model, escalation paths 

2. Information gathering 

Assets, data sources, access requirements 

3. System configuration 

Platform, sensors, vulnerability scanning 

4. System integration 

Tool connections, compliance framework mapping 

5. Hardening and tuning 

Alert tuning, threshold calibration, validation 

6. Steady-state delivery 

24/7 SOC, monthly reporting, continuous improvement 

If you are evaluating enhanced.io and want to understand what this looks like for your specific environment, book some time with me and I will walk you through a proof of concept scope before you commit to anything. 


About enhanced.io 

enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every partner works with a named, CISSP-certified Fractional Security Director, backed by a 24/7 SOC. enhanced.io never sells direct to end clients. Book a partnership conversation with me

FAQ

How long does enhanced.io onboarding take for a new MSP partner?

Typically 30 to 45 days from kickoff to steady-state delivery, scoped to what is being onboarded. It runs across 6 phases: kickoff, information gathering, system configuration, system integration, hardening and tuning, then steady-state service delivery. Hardening and tuning are included in that window. The figure is an indicative average rather than a fixed timeline, and some onboardings run faster. 

What affects how long onboarding takes?

Site configuration, the size of the environment and, most of all, how fast you supply the information we ask for. You complete the onboarding forms and enhanced.io does the onboarding. Some environments need a firewall reconfiguration, and a site with no virtualization needs a physical sensor, both of which add time. 

Do I need to replace my existing security tools to onboard with enhanced.io?

No. enhanced.io integrates with 400+ security and IT tools, so in most cases your existing stack, including your EDR, connects without a rip-and-replace. The platform adds coverage across network, cloud, identity and IoT/OT rather than replacing what you already have.

What does a Fractional Security Director do during onboarding?

Your FSD is a named, CISSP-certified security professional who runs the kickoff call, stays involved through every onboarding phase and leads the monthly risk management meetings once you are in steady state. It is the same person throughout, not a setup team who hands off once configuration is done. 

What happens during the hardening and tuning phase?

We reduce false positives, calibrate detection thresholds to each client's risk profile, validate that escalation paths work before a live incident and confirm compliance reporting maps correctly. This happens before go-live, and it is what makes the alerts meaningful once you are live. 

Which compliance frameworks does enhanced.io support during onboarding?

CMMC, NIS2, DORA, HIPAA, ISO 27001, NIST CSF and Essential Eight. Mapping your data sources to whichever frameworks your clients need happens during the system integration phase, so compliance reporting is built in rather than added later. 

What does steady-state delivery look like after onboarding?

24/7 SOC monitoring and response, monthly risk management meetings with your FSD, an automated threat assessment report in the first week of every month and continuous tuning as your client environments change.