Thu, 1 Oct 2026

MSPs step up as acting CISO for nearly half of customers

Managed service providers (MSPs) have quietly become the de facto CISO for 46% of their customers on average, according to new research from cybersecurity firm Sophos.

The trend is set to accelerate, with 84% of MSPs expecting demand for CISO-level guidance to rise over the next 12 months as organisations grapple with AI-driven risk, compliance obligations and increasingly complex security environments.finance.

The findings come from Sophos’ 2026 MSP Perspectives Report, based on an independent survey of 800 senior MSP stakeholders across the US, UK, Germany, France, Singapore, Australia and Brazil. While MSPs have traditionally focused on deploying and managing IT and security technologies, many customers now rely on them for strategic cybersecurity leadership, governance and risk advice that they cannot sustain in-house.

“Organisations require more than technology management to stay secure. They need trusted cybersecurity leaders who can help them understand their risk, navigate compliance requirements and translate security investments into meaningful business outcomes,” said Scott Barlow, vice-president and chief evangelist at Sophos.

“MSPs are already stepping into this role for nearly half of their customers, creating a significant opportunity to deepen relationships and develop new, higher-value services. The challenge now is delivering that leadership consistently and efficiently across a growing customer base.”

Compliance is central to this expanding remit. Nearly all MSPs surveyed (99%) provide at least one cybersecurity compliance service, and 58% offer full compliance programme management, though only 6% deliver the full range of compliance services evaluated in the research.

On average, compliance influences 50% of customer cybersecurity purchasing decisions, with a third heavily or decisively driven by regulatory demands.

Related:  HKCERT warns AI, supply chain and staffing gaps are reshaping HK cyber risk

Despite high participation, delivery remains fragmented. Just 36% of MSPs use a single platform to centrally manage compliance or CISO-type activities, while 53% juggle multiple tools. MSPs estimate they would save 53% of their time with a unified platform for security posture and compliance management, and 81% believe it would cut time spent on these tasks by more than 30%.

Automation also has room to grow: while 86% use fully or semi-automated processes for consolidated security posture reports, only 31% can generate them quickly through full automation.

To help MSPs scale this role, Sophos will launch CISO Advantage in October 2026, delivered through its AI-native Fusion cybersecurity defence system. The service uses agentic AI-accelerated assessment, reporting and roadmap workflows to produce board-ready insights, framework-mapped evidence and prioritised action plans across an MSP’s customer base.

Related Stories

MORE STORIES