Skip to content

Security1 publisher2 min readPublished

MSPs say 46% of their customers now look to them for CISO-level leadership

Sophos's 2026 MSP Perspectives Report has 84% of providers expecting that demand to grow over the next 12 months, while 31% can fully automate reports at speed and 55% still consolidate activity by hand.

The Watch · Security desk

Illustration accompanying MSPs say 46% of their customers now look to them for CISO-level leadership

What happened

  • Sophos's 2026 MSP Perspectives Report says managed service providers estimate that 46% of their customers look to them for CISO-level leadership, a figure the providers themselves supplied.
  • Eighty-four percent of the providers surveyed expect demand for those CISO services to increase over the next 12 months.
  • Compliance or CISO-type activity is managed across multiple tools or platforms at 53% of the providers; no single system consolidates it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Growth in these services is priced in headcount: the report ties every extra customer, framework and assessment to more resources and more governance.
  • cost With compliance shaping half of purchasing decisions, a partial compliance practice costs the provider deals.
  • exposure Organizations that outsource risk prioritization and posture verification are relying on a provider whose evidence pipeline still has a person in it.
  • decision The testable question in a CISO-services pitch is how fast an audit-ready report arrives without someone assembling it by hand.

"CISO-level" in the report means specific work: assessing how controls perform, managing compliance programs, and helping customers understand risk, prioritize security investment, demonstrate compliance and verify their security posture [11]. The 46% is the providers' own estimate of what their customers want from them, and the customers themselves were not surveyed [1]. Sophos writes that MSPs are "now the de facto CISO for many of their customers, and demand is only expected to increase" [12].

Thirty-one percent can fully automate reports at speed, and 69% cannot [7][1]. Fifty-five percent still need some manual effort to consolidate activities, including those already using automation [8]. Slightly over half, 53%, run that consolidation across multiple tools or platforms [6]. On breadth, 99% sell at least one compliance service and 6% sell all seven the report counted, so 94% are running a partial practice [3][4][2].

That manual step sits between an auditor's request and the answer. The report says compliance influences 50% of customer purchasing decisions [5]. It also says each additional customer, framework, assessment and reporting requirement needs more resources and more governance, and that providers who add service volume without addressing the complexity risk putting pressure on already stretched teams [9]. Nothing in the report describes an intrusion.

Sophos sells security tooling to MSPs, and the report's closing section is headed "The untapped opportunity: unification and scale" [13]. The blog post summarizing the findings gives no respondent count and no detection-coverage figures [14]. What the numbers support is narrow: among the providers surveyed, compliance breadth reaches all seven services in 6% of cases and reporting is fully automated in 31% [4][7].

The report's own diagnosis is that compliance practices remain incomplete, delivery is fragmented across different tools, and much of the reporting process still requires manual effort [10]. All three problems belong to the provider, and the customer is the one buying risk judgment from it.

What to watch

  • Whether Sophos publishes the full report with a respondent count, country breakdown and the wording behind the 46% estimate.
  • Whether the 84% demand expectation turns up in contract language, with report turnaround and evidence delivery written into MSP agreements.
  • Whether the 6% offering all seven compliance services moves in the next edition of the survey.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories