top of page

A Service Review that evolves over time

  • Writer: Guy Galon
    Guy Galon
  • 18 hours ago
  • 3 min read

A service review format that hasn't changed in twelve months isn't a service review. Even if it is successful and clients love it, it cannot become a habit or remain the Customer Success team's comfort zone.


Over the past few months, my team at Obrela reverse-engineered our service review and rebuilt it.  The objective was to make it sharper, more useful, and practical to the people sitting on the other side of the table.


Here is what that work surfaced.


Clients don't attend because the invitation is in the calendar

They attend because cybersecurity now sits on the board agenda, and because business disruption is the one risk every executive wants to minimize. When they walk into the room, they want two answers. How exposed they are right now, and what they can do jointly with Obrela about it.


The biggest change we made was adding professional observations.

Not a longer metrics pack.  We have enough data to present; our clients can review it in detail before or after the service review. We build the observations from the statistics and the analysis behind them, and each one names a specific gap in the client's security posture.


That gap can increase specific risks. The recommendations then follow from those observations, making them narrower, risk-related, better grounded, and far easier to act on: same underlying data, different output.


The metrics themselves are close to what we presented in earlier versions of the review.

What changed is the emphasis. We now spend more of the meeting on the categories of security cases reported to the client, and on the potential impact of each category on their environment and their business.


So the meeting has to cover three things:

•      The KPIs the service is measured on.

•      Our honest assessment of the risk and exposure the client is carrying today.

•      The recommendations, split by owner. Some actions are ours. Some are theirs. No room for ambiguity about which is which.


Then the harder part: measuring progress

A single service review tells a client where they stand. A sequence of them tells the client whether they are getting safer.

We encourage clients to run active simulations, because an untested defense will fail in a critical moment. We also brief them on the threat groups and actors most likely to target their business, narrowed to their geography and to the techniques those actors employ.


And we ask what has changed on their side.

New systems, new applications, revised policies, a reorganization, an acquisition. We already know about some of these. For many, we have to ask intentionally. Everyone reshapes the attack surface, and if the information gap surfaces six months late, our recommendations may as well be out of date.


Keeping a business safe is a standing effort, not a milestone. A clean quarter guarantees nothing about the next one.


The invisible impact problem isn't only ours

In cybersecurity, outcomes are usually invisible.

Nobody thanks a vendor for a breach that never happened. But any CS leader whose product reduces cost, mitigates risk, or removes operational friction faces the same challenge. The value is real, and the evidence is quiet.


The service review is where that invisible work gets a chance to feature on the main stage, and it has to perform. That's why the format itself has to keep evolving.

 

Practitioner Tip for TheCSCycle Readers

Audit the format, not just the content.

  1. Select the latest QBR or service review version.

  2. For each slide, ask the following questions:

“What purpose does it serve?”

“What will the client learn from this slide?”

“Are we helping the client to improve or change anything that is not correct or efficient?”


  1. Overall, aim to reduce the number of slides, include more observations the client will not notice, and provide useful recommendations.

 

Competitive pressure, AI, and executive expectations all move faster and may make our templates and content irrelevant.

A format that worked twelve months ago may be twelve months behind your client's reality.

 

This is one of the frameworks I explore with CS executives inside TheCSCycle. If this resonates with where you are today, visit thecscycle.com to learn more.

Comments


bottom of page