A survey by Sophos of 800 managed service providers finds that nearly half of their customers already treat them as an outsourced CISO. But compliance portfolios remain incomplete, reporting still depends on manual work, and providers themselves estimate a unified platform would give back more than half of their teams’ time.

Cybersecurity has a leadership shortage, and managed service providers are quietly filling it. According to the Sophos MSP Perspectives 2026 report, published in September 2026, MSPs estimate that 46 percent of their customers already look to them to act as their Chief Information Security Officer. But they are running that role on toolchains never designed for it.

The study is based on an independent, vendor-agnostic survey of 800 senior and board-level MSP stakeholders, conducted by research house Vanson Bourne in April 2026 and commissioned by Sophos. Respondents came from seven markets: the United States (200), plus the UK, Germany, France, Singapore, Australia and Brazil with 100 each.

The starting point, according to the report, is a structural gap. There is roughly one CISO for every 10,000 organisations worldwide, leaving most companies without dedicated security leadership at a time when incidents, regulation and security budgets are all rising. The consequence is that customers are pushing strategic responsibility onto their service providers.

The numbers show how far that has gone. Some 88 percent of MSPs act as the CISO for more than a fifth of their customer base, 40 percent for more than half, and 20 percent for more than 70 percent of customers. Demand is expected to keep climbing: 84 percent anticipate growth in CISO-type services over the next twelve months, including 23 percent who expect a significant increase. Only 2 percent expect a decline.

Compliance is the commercial engine behind this shift. Virtually all providers surveyed, 99 percent, offer at least one compliance service, and between 58 and 64 percent deliver each of the seven activities measured, from identifying applicable frameworks to submitting audit responses. Compliance also shapes what customers buy: MSPs say it influences half of cybersecurity purchases on average and is a heavy or decisive factor in a third of them.

Breadth, however, is not the same as maturity. Only 6 percent of MSPs provide all seven compliance services; 70 percent offer between four and six. The pattern repeats one level up. Of the 58 percent of providers that manage a customer’s entire compliance programme, just 10 percent also deliver all six supporting services, and 46 percent deliver three or fewer. Programme-level responsibility is frequently taken on before the underlying service stack exists, with activities coordinated across customers or third-party specialists rather than delivered directly.

Size explains less than might be expected. MSPs with 51 or more employees are the most likely to offer all seven services, at 10 percent, but the smallest providers, with up to five staff, report the highest average number of services delivered. Full programme management is adopted at similar rates across every size band, from 54 to 62 percent, suggesting that competition is shifting from whether a service is offered to how quickly and completely it is delivered.

Confidence in continuous compliance is high but not absolute. Some 95 percent describe themselves as very or completely confident in their ability to continuously monitor, manage and document compliance across multiple customers, yet only 33 percent choose the stronger option. German and British MSPs report the least difficulty identifying and remediating compliance and control gaps, both at 89 percent, ahead of the United States at 81 percent, while Singapore trails at 72 percent.

The operational picture is where the report is least flattering. Tool-based delivery is now standard, with 89 percent of MSPs using at least one platform to manage compliance or CISO-type work centrally. But consolidation has not followed: 53 percent run multiple tools against 36 percent on a single system, and 9 percent still work entirely manually. Many of those tools cannot feed a central reporting layer, forcing staff to assemble customer-facing reports by hand.

That shows up in reporting maturity. While 86 percent of providers use fully or semi-automated processes to produce consolidated security posture reports, only 31 percent can generate them quickly end to end. The remaining 55 percent still add manual effort to combine data, supply context and finalise documents. Providers at every level of automation are running multiple tools, which suggests fragmentation rather than sophistication.

Asked what a single unified platform would be worth, MSPs put the figure at 53 percent of the time their teams spend managing and reporting on customer security posture and compliance. Some 81 percent expect savings above 30 percent, and 22 percent above 70 percent. The estimate rises among those already doing the hardest work: 84 percent of providers offering full compliance programme management expect savings of more than 30 percent, against 64 percent of those with no plans to offer it.

The conclusion is uncomfortable for the channel. In taking on CISO-style responsibility, MSPs have inherited the tooling sprawl and reporting burden that in-house security teams have struggled with for years. Sophos positions its own CISO Advantage offering, delivered through its Fusion platform, as the answer, and the survey was commissioned by the vendor. The underlying finding stands on its own: demand for outsourced security leadership is running ahead of the operational model available to deliver it.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner