From sign-up to fully protected: how enhanced.io onboards new MSP partners in 90 days

From sign-up to fully protected: how enhanced.io onboards new MSP partners in 90 days

Loading the Elevenlabs Text to Speech AudioNative Player...

About Author

Hannah Lloyd

Hannah Lloyd is CRO and co-founder of enhanced.io. She leads global new business generation and works directly with MSP partners to build and sell security practices.

enhanced.io, the channel-only Open XDR SOCaaS for MSPs

TL;DR

  • enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.

  • A new MSP partner goes from kickoff to steady-state delivery in around 90 days, across 6 phases, with a named CISSP-qualified Fractional Security Director alongside you the whole way.

  • Your existing stack connects rather than getting replaced. enhanced.io integrates with 400+ security and IT tools, so onboarding is not a rip-and-replace project.

  • Weeks 8 to 12 are about hardening and tuning, not only going live. The goal is to be confident by day 90, not only operational.

  • Steady state means 24/7 SOC monitoring, monthly risk reviews with your FSD, and a monthly automated threat assessment report to put in front of clients.

One of the first things MSPs ask me when they're weighing up a new security platform is some version of the same question. This all sounds great, but how long before we're up and running?

It's a fair question, and I don't think enough vendors answer it honestly. Most of the MSPs I talk to have been burned before by a vendor who promised a smooth deployment and then left them drowning in configuration work, undocumented APIs, and a support queue that moved slower than a SIEM alert at 2am.

So here is the honest answer, and I mean the whole thing, not the marketing version. enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Onboarding a new partner onto that platform takes around 90 days from kickoff to steady-state delivery, not 90 days of chaos, but 90 days of a structured, guided process where we do the heavy lifting alongside you.

The six phases below are what that looks like in practice, step by step.

Phase 1: kickoff and service alignment (week 1)

The first thing that happens once you're on board is a kickoff call with your key stakeholders and your dedicated Fractional Security Director, or FSD. This is not a generic onboarding webinar, and I always tell partners not to expect a slide deck marathon. It's a working session built around your specific scope, objectives and delivery approach, and it happens before a single sensor gets deployed.

Your FSD is a named, CISSP-qualified security professional who sits between the enhanced.io SOC, your MSP team, and your end clients. They're with you from day one, not handed over once some anonymous setup team has finished the technical work, and in my experience that continuity is what partners end up valuing most six months in.

What gets covered in kickoff

  • Scope definition: which client environments are being brought under monitoring

  • Delivery model: whether you're running full 24/7 SOC support, platform-only, or a blended approach

  • Escalation paths: who gets called, when, and how

  • Success criteria: what "done" looks like at the end of 90 days

Getting this alignment locked in early is what makes everything downstream move faster. When scope is clear, configuration moves faster. When escalation paths are agreed up front, response is cleaner. It sounds obvious when I put it like that, but most onboarding failures I've seen start right here, with assumptions nobody bothered to write down.

Phase 2: information gathering (weeks 2 to 3)

Before effective monitoring is possible, we need to understand what we're protecting. This phase is largely a documentation exercise, and we try to keep it lean rather than asking your team to fill out a 40-page questionnaire.

What we gather:

  • Critical assets: servers, endpoints, cloud workloads, OT/IoT devices, and any BMS environments in scope

  • Data sources: which tools and platforms are already generating logs and telemetry

  • Access requirements: credentials, API keys, and network access needed to connect the platform

  • Escalation contacts: who on your team needs to be looped in for different alert severities

Worth noting: enhanced.io integrates with over 400 security and IT tools, so in most cases your existing stack connects without any rip-and-replace. We work around what you already have, not the other way round.

Phase 3: system configuration (weeks 3 to 5)

With the information gathered, we configure the platform to match your environment. This covers the Open XDR platform itself, network sensors, and vulnerability scanning, all set up around your specific setup and goals rather than a generic template.

What we configure

  • The Open XDR platform: data ingestion pipelines, correlation rules, and detection logic tuned to your client environments

  • Network sensors: deployed to capture east-west and north-south traffic across physical, virtual, and cloud infrastructure

  • Vulnerability scanning: configured against your in-scope assets, ready to produce the monthly remediation reports your clients will see

This is where the depth of enhanced.io's visibility starts to become obvious. Most endpoint-only solutions miss the lateral movement happening between devices on the same network, and by deploying network sensors alongside your existing EDR, we cover the attack surface that agents simply cannot see. Your EDR keeps doing what it does best, and our sensors cover everything else, working alongside it rather than competing for the same job.

Phase 4: system integration (weeks 5 to 8)

Configuration sets the platform up. Integration connects it to everything else. In this phase we bring in your security tools and platforms, apply the required security controls, and set the access policies that govern how data flows between systems.

This is also where your existing stack gets properly wired in, whether that is Microsoft 365, Google Workspace, Okta, AWS, Azure, or some combination of all of them. The platform correlates signals across identity, SaaS, cloud, network and endpoint into a single view, so your SOC analysts are not switching between six dashboards to work out what is happening in a client environment.

For MSPs with clients in regulated industries, this phase also covers mapping your data sources to the relevant compliance frameworks. enhanced.io supports CMMC, NIS2, DORA, HIPAA, ISO 27001, NIST CSF and Essential Eight, so the reporting your clients need is built into the platform rather than bolted on afterward.

Phase 5: hardening and tuning (weeks 8 to 12)

This is the phase that separates a well-deployed security platform from one that generates noise. Once the integrations are live and data is flowing, we run baseline hardening and alert tuning aligned to recognised security frameworks and best practice.

In practical terms, that means:

  • Reducing false positives so your team is not chasing phantom alerts

  • Calibrating detection thresholds to match the risk profile of each client environment

  • Validating that escalation paths work as expected before you are in a live incident

  • Confirming that compliance reporting maps correctly to the frameworks your clients need

By the end of this phase, the platform is not only running, it is running well. The SOC team knows your environment, the alerts are meaningful, and your FSD has a clear picture of your clients' security posture. The goal was never only to be live by day 90. It is to be confident by day 90, and there is a real difference between the two.

Phase 6: steady-state service delivery (day 90 onward)

Once hardening is complete, you move into steady-state delivery. This is where the 24/7 SOC takes over as the operational backbone, and the relationship shifts from getting set up to running well and improving continuously.

What steady state looks like in practice

  • 24/7 SOC monitoring and response: the enhanced.io SOC is watching your client environments around the clock, with automated triage cutting through the noise and expert analysts handling what matters

  • Monthly risk management meetings: your FSD leads regular reviews of security posture, outstanding vulnerabilities, and any changes to client environments

  • Automated threat assessment reports: delivered in the first week of every month, covering the Open XDR platform's findings alongside vulnerability remediation priorities, so you have something concrete to show clients

  • Continuous tuning: the platform does not stay static, and as your client environments evolve, the detection logic evolves with them

For MSPs, this is the part that changes the business model. Instead of reactive firefighting, you are delivering a proactive, documented security service with monthly reporting your clients see and understand, and that is what justifies the margin and makes the contracts sticky.

Once you are a partner, you get the full onboarding timeline and the supporting documentation that sits behind it, including the RACI matrix, statements of work, and sample threat assessment reports, so nothing here is a surprise once you are underway.

The short version

90 days. Six phases. A named CISSP alongside you from day one. No rip-and-replace of your existing tools, and no building a SOC from scratch.

Here is the full timeline at a glance:

Phase

Focus

Timing

1. Kickoff

Scope, delivery model, escalation paths

Week 1

2. Information gathering

Assets, data sources, access requirements

Weeks 2 to 3

3. System configuration

Platform, sensors, vulnerability scanning

Weeks 3 to 5

4. System integration

Tool connections, compliance framework mapping

Weeks 5 to 8

5. Hardening and tuning

Alert tuning, threshold calibration, validation

Weeks 8 to 12

6. Steady-state delivery

24/7 SOC, monthly reporting, continuous improvement

Day 90 onward

If you are evaluating enhanced.io and want to understand what this looks like for your specific environment, book some time with me and I will walk you through a proof of concept scope before you commit to anything.

About enhanced.io

enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. Every partner works with a named, CISSP-certified Fractional Security Director, backed by a 24x7 SOC. enhanced.io never sells direct to end clients. Book a partnership conversation with me.

FAQ

How long does enhanced.io onboarding take for a new MSP partner?

Around 90 days from kickoff to steady-state delivery across your book of business, spanning 6 phases: kickoff, information gathering, system configuration, system integration, hardening and tuning, and steady-state service delivery. Bringing an individual client environment under coverage once you are already a partner is faster, typically 30 to 45 days depending on what is being onboarded.

Do I need to replace my existing security tools to onboard with enhanced.io?

What does a Fractional Security Director do during onboarding?

What happens during the hardening and tuning phase?

Which compliance frameworks does enhanced.io support during onboarding?

What does steady-state delivery look like after the 90 days?