
Three tiers, separated by what gets watched rather than by how fast you answer. Clients understand surfaces. They do not understand response-time bands, and selling on those turns every renewal into a haggle over minutes. Tier on coverage, price on outcome, and keep the response commitment identical across all three.
Why tier on coverage rather than response time?
A client picturing an unwatched cloud tenant buys the upgrade. A client comparing a 15-minute SLA to a 30-minute SLA negotiates. Coverage is a decision about risk, response time is a decision about price.
What goes in each tier?
Entry covers endpoint and identity. Middle adds cloud and network. Top adds IoT and OT, which is where regulated and manufacturing clients land. Vulnerability management and compliance reporting sit in every tier, because removing them creates an argument.
What should never be a tier?
The named security contact, the response commitment, and reporting. Charging for those tells a client the cheaper tier is the one you care less about.
Why tier on coverage rather than response time?
A client picturing an unwatched cloud tenant buys the upgrade. A client comparing a 15-minute SLA to a 30-minute SLA negotiates. Coverage is a decision about risk, response time is a decision about price.
What goes in each tier?
Entry covers endpoint and identity. Middle adds cloud and network. Top adds IoT and OT. Vulnerability management and compliance reporting sit in every tier.
What should never be a tier?
The named security contact, the response commitment, and reporting.
Next step
To see how this maps to your client estates, book a partnership conversation with Hannah Lloyd at https://meetings.hubspot.com/hannah-lloyd.


