MSPs Have Quietly Become Acting CISO for Nearly Half of Their Customers: Sophos
Sophos,
a global cybersecurity leader, today released its 2026 MSP Perspectives Report,
revealing that managed service providers (MSPs) are playing an increasingly
strategic role in helping organisations manage cyber risk. Traditionally
responsible for deploying, managing and supporting IT and cybersecurity
technologies, MSPs are increasingly being called upon to provide the
cybersecurity leadership, governance and risk guidance that many organizations
do not have the resources to maintain in-house.
On
average, MSPs estimate that nearly half (46%) of their customers currently rely
on them to act as their Chief Information Security Officer (CISO). New research
suggests this role will continue to expand, with 84% of MSPs expecting demand
for CISO services to increase over the next 12 months as organizations seek
trusted advisors to help navigate cybersecurity risk, compliance obligations
and increasingly complex security environments.
“Organizations
require more than technology management to stay secure. They need trusted
cybersecurity leaders who can help them understand their risk, navigate
compliance requirements and translate security investments into meaningful
business outcomes,” said Scott Barlow, vice president and chief evangelist at
Sophos. “MSPs are already stepping into this role for nearly half of their
customers, creating a significant opportunity to deepen relationships and
develop new, higher-value services. The challenge now is delivering that
leadership consistently and efficiently across a growing customer base.”
The
opportunity to create efficiencies is also vast, with MSPs estimating they
would save 53% of their time if they could use a single, unified platform for
customer security posture and compliance management and reporting.
Additionally, 81% believe it would reduce the time they currently spend on
these activities by more than 30%.
Compliance
is also central to this expanding role. Nearly all MSPs surveyed, 99%, provide
at least one cybersecurity compliance service, and 58% currently offer full
compliance program management. However, just 6% offer the full range of
compliance services evaluated in the research, highlighting a gap between broad
participation in compliance and the delivery of a comprehensive service stack.































Leave A Comment