Reports
  MSPs Have Quietly Become Acting CISO for Nearly Half of Their Customers: Sophos

MSPs Have Quietly Become Acting CISO for Nearly Half of Their Customers: Sophos

Sophos, a global cybersecurity leader, today released its 2026 MSP Perspectives Report, revealing that managed service providers (MSPs) are playing an increasingly strategic role in helping organisations manage cyber risk. Traditionally responsible for deploying, managing and supporting IT and cybersecurity technologies, MSPs are increasingly being called upon to provide the cybersecurity leadership, governance and risk guidance that many organizations do not have the resources to maintain in-house.

On average, MSPs estimate that nearly half (46%) of their customers currently rely on them to act as their Chief Information Security Officer (CISO). New research suggests this role will continue to expand, with 84% of MSPs expecting demand for CISO services to increase over the next 12 months as organizations seek trusted advisors to help navigate cybersecurity risk, compliance obligations and increasingly complex security environments.

“Organizations require more than technology management to stay secure. They need trusted cybersecurity leaders who can help them understand their risk, navigate compliance requirements and translate security investments into meaningful business outcomes,” said Scott Barlow, vice president and chief evangelist at Sophos. “MSPs are already stepping into this role for nearly half of their customers, creating a significant opportunity to deepen relationships and develop new, higher-value services. The challenge now is delivering that leadership consistently and efficiently across a growing customer base.”

 

The opportunity to create efficiencies is also vast, with MSPs estimating they would save 53% of their time if they could use a single, unified platform for customer security posture and compliance management and reporting. Additionally, 81% believe it would reduce the time they currently spend on these activities by more than 30%.

 

Compliance is also central to this expanding role. Nearly all MSPs surveyed, 99%, provide at least one cybersecurity compliance service, and 58% currently offer full compliance program management. However, just 6% offer the full range of compliance services evaluated in the research, highlighting a gap between broad participation in compliance and the delivery of a comprehensive service stack.

 

Leave A Comment