AGP Picks
View all

MSPs Have Quietly Become Acting CISO for Nearly Half of Their Customers, Sophos Research Finds

As AI-driven risk accelerates, 84% of MSPs say demand for CISO-level guidance is surging, while simultaneously citing risks to sufficiently scale to meet demand

OXFORD, United Kingdom, Sept. 15, 2026 (GLOBE NEWSWIRE) -- Sophos, a global cybersecurity leader, today released its 2026 MSP Perspectives Report, revealing that managed service providers (MSPs) are playing an increasingly strategic role in helping organizations manage cyber risk. Traditionally responsible for deploying, managing and supporting IT and cybersecurity technologies, MSPs are increasingly being called upon to provide the cybersecurity leadership, governance and risk guidance that many organizations do not have the resources to maintain in-house.

On average, MSPs estimate that nearly half (46%) of their customers currently rely on them to act as their Chief Information Security Officer (CISO). New research suggests this role will continue to expand, with 84% of MSPs expecting demand for CISO services to increase over the next 12 months as organizations seek trusted advisors to help navigate cybersecurity risk, compliance obligations and increasingly complex security environments.

“Organizations require more than technology management to stay secure. They need trusted cybersecurity leaders who can help them understand their risk, navigate compliance requirements and translate security investments into meaningful business outcomes,” said Scott Barlow, vice president and chief evangelist at Sophos. “MSPs are already stepping into this role for nearly half of their customers, creating a significant opportunity to deepen relationships and develop new, higher-value services. The challenge now is delivering that leadership consistently and efficiently across a growing customer base.”

The opportunity to create efficiencies is also vast, with MSPs estimating they would save 53% of their time if they could use a single, unified platform for customer security posture and compliance management and reporting. Additionally, 81% believe it would reduce the time they currently spend on these activities by more than 30%.

Compliance is also central to this expanding role. Nearly all MSPs surveyed, 99%, provide at least one cybersecurity compliance service, and 58% currently offer full compliance program management. However, just 6% offer the full range of compliance services evaluated in the research, highlighting a gap between broad participation in compliance and the delivery of a comprehensive service stack.

Other findings from the MSP Perspectives 2026 Report include:

  • Compliance drives security investment: Compliance influences 50% of customer cybersecurity purchasing decisions on average, with 33% heavily or decisively influenced by regulatory demands. This creates an opportunity for MSPs to connect compliance requirements with broader security priorities.
  • The shift to continuous compliance is gradual: Only 33% of MSPs are “completely confident” in their ability to continuously monitor, manage, and document compliance across multiple customers, highlighting a gap between the certainty customers need from their partners and what MSPs can consistently deliver.
  • Tool-based delivery is commonplace, but fragmented: While 36% of MSPs rely on a single tool or platform to centrally manage cybersecurity compliance or CISO-type activities, 53% use multiple tools or platforms, indicating that delivery remains complex, disjointed, and potentially harder to scale.
  • Full automation of security reporting has room to grow: While 86% of MSPs use a fully or semi-automated process to produce consolidated security posture reports, 55% still require some manual effort and just 31% can generate reports quickly through a fully automated process.

“MSPs have an opportunity to become indispensable strategic partners to their customers, but scaling that role requires a more unified operating model,” continued Barlow. “Bringing security posture, compliance management and reporting together can help MSPs spend less time manually consolidating information and more time helping customers reduce risk, strengthen resilience and make informed cybersecurity decisions.”

Sophos CISO Advantage, available beginning October 2026, is designed to help MSPs turn the CISO role many already perform into a structured, scalable and billable cyber program management service. Delivered through Sophos Fusion, the company’s AI-native Cybersecurity Defense System, Sophos CISO Advantage uses agentic AI-accelerated assessment, reporting and roadmap workflows to support board-ready insights, framework-mapped evidence and prioritized action plans across an MSP’s customer base and prioritized action plans across an MSP’s customer base.

Data for the MSP Perspectives 2026 report comes from an independent, vendor-agnostic survey of 800 MSPs across the United States, United Kingdom, Germany, France, Singapore, Australia and Brazil. Respondents represented senior to board-level MSP stakeholders. The survey was commissioned by Sophos and conducted by Vanson Bourne in April 2026.

Click here to read the full MSP Perspectives 2026 report.

To learn more about Sophos CISO Advantage, MSPs can visit the Sophos Partner Portal.

Organizations interested in becoming a Sophos Partner can register here.

About Sophos
Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Contact: Kelly Archer, kelly.archer@sophos.com.


Primary Logo

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Hong Kong Tech Press

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.