Turn virtual desktops into business growth

Rethinking VDI

How MSPs Can Stop Selling One-Off Deployments and Start Selling Compliance-Driven Solutions

VDI does not have to be another price-compared line item. The book reframes it as the delivery engine for a complete solution built around regulated workloads, cybersecurity controls, and measurable business outcomes.

  • MSP Strategy
  • Compliance
  • VDI
  • Cyber Insurance
RETHINKING VDICHRISTOPHER L. BUFORD
Front cover of Rethinking VDI by Christopher L. Buford

The central reframe

VDI was never the whole product.

When an MSP sells VDI by itself, the conversation can collapse into features and price. Rethinking VDI shows how to reposition the platform as the workhorse behind a broader, compliance-driven solution.

The book connects the technology to vertical focus, packaging, pricing, positioning, sales conversations, and delivery.

Inside the book

Build the offer around the outcome, not the parts.

The framework starts with a narrow regulated sub-vertical, then builds a packaged offer around the specific compliance or risk problem that market must solve.

VDI as the workhorse

Move VDI from a standalone SKU to the central delivery layer for applications, data, and controlled user sessions.

Niche down further

Target smaller feeder markets and sub-verticals with specific regulatory requirements instead of competing across broad industries.

Backup & recovery

Connect recovery and business continuity to the complete solution rather than selling backup as an isolated line item.

AI

Contained AI access

Use the VDI session as a controlled environment for AI access and address shadow-AI risk as part of the larger offer.

Secure access & zero trust

Wrap the delivery environment with access verification and zero trust controls that support the intended compliance outcome.

Package, price, and sell

Move from line-item pricing to a single packaged outcome, then position and sell it around the client’s business risk.

One architecture. Multiple business cases.

A delivery engine for secure, regulated work.

In the book’s model, the VDI environment carries most of the delivery burden. Backup, secure browser capabilities, contained AI access, and zero trust controls connect to or wrap around that environment.

For manufacturing and CMMC, the same pattern can become a tightly scoped secure enclave for Controlled Unclassified Information, keeping the assessment boundary smaller and more defensible.

Four core examples

Go narrower than “we do healthcare” or “we do manufacturing.”

HealthcareHIPAA + vendor-specific EHR requirements
Behavioral Health42 CFR Part 2
Financial ServicesReg S-P, S-ID + SEC cybersecurity requirements
ManufacturingCMMC + CUI secure-enclave scoping

A second sales angle

Compliance is not the only reason the buyer cares.

Cybersecurity insurance

The book connects the same access, segmentation, backup, recovery, and AI-control practices to the kinds of technical-control questions clients face when applying for or renewing cyber insurance.

That gives an MSP a complementary way to frame the solution for clients who may not lead with regulatory compliance.

The book

Front and back cover

Front cover of Rethinking VDI
Front cover
Back cover of Rethinking VDI
Back cover with reserved ISBN barcode area

Built to be used

Strategy, story, and an action step at the end of every chapter.

Each chapter opens with a scene from a fictional MSP owner’s journey, moves into direct teaching that stands on its own, and closes with a worksheet, reflection, or real-world action step.

The result is a business book designed to move the reader from idea to implementation.

Christopher L. Buford, author of Rethinking VDI
Author of Rethinking VDI

About the author

Christopher L. Buford

AI Governance • Cloud Security • Virtualization • MSP Strategy

Christopher L. Buford brings more than 25 years of experience across enterprise IT, virtualization, cloud, cybersecurity, managed services, and technical go-to-market strategy. His work increasingly sits at the intersection of AI governance, AI security, cloud security, and controlled application delivery - helping organizations think beyond simply adopting AI toward governing how data, users, applications, and AI systems interact.

He holds the AIGP (Artificial Intelligence Governance Professional), CCSP (Certified Cloud Security Professional), and CCSK (Certificate of Cloud Security Knowledge) credentials, along with certifications spanning AWS, agile delivery, IT service management, identity, and vulnerability management. That combination of AI governance, security architecture, and hands-on infrastructure experience shapes the central argument of Rethinking VDI: MSPs can use VDI as a controlled delivery layer for secure access, regulated data, contained AI use, backup and recovery, and broader compliance-driven services.

His focus is practical: translate technical controls into a defined market, a compliance or risk outcome, and an offer an MSP can package, price, sell, and deliver.

  • AI Governance
  • AI Security
  • Cloud Security
  • Virtualization & VDI
  • Managed Services
  • Compliance-Driven GTM

Questions MSP owners ask

Rethinking VDI - FAQ

Who is this book written for?

MSP owners who want to move away from selling isolated VDI deployments and build packaged, outcome-based solutions for narrower regulated markets.

What is the core idea?

VDI becomes the delivery engine for a larger solution rather than the entire product. Other controls and services connect to it or wrap around it to solve a defined compliance or risk problem.

Does the book only apply to healthcare?

No. The core examples include healthcare, behavioral health, financial services and RIAs, and manufacturing.

Where does CMMC fit?

The manufacturing example uses VDI as a secure enclave for CUI so the compliance boundary can be contained rather than spread across every endpoint and device.

Why does the book discuss cyber insurance?

The same access, segmentation, backup, recovery, and AI-control practices can support responses to common cyber-insurance underwriting questions, creating a complementary business case for the MSP’s packaged offer.

Is this mainly a technical book?

No. The architecture is only part of the framework. The book also covers vertical selection, offer packaging, pricing, positioning, sales conversations, and rollout planning.

Stop selling the tool. Sell the outcome.

Rethink what VDI can become inside an MSP services business.

By Christopher L. Buford

Find Rethinking VDI on Amazon