Managed service providers (MSPs) are increasingly taking on cybersecurity leadership responsibilities for their customers, with MSPs reporting that 46% of their customers rely on them to act as their Chief Information Security Officer (CISO), according to Sophos’ 2026 MSP Perspectives Report.
The research also found that 84% of MSPs expect demand for CISO-level services to increase over the next 12 months, as organisations seek support with cybersecurity risk, compliance and security governance.
“Organisations require more than technology management to stay secure. They need trusted cybersecurity leaders who can help them understand their risk, navigate compliance requirements and translate security investments into meaningful business outcomes,” said Scott Barlow, Vice President and Chief Evangelist at Sophos.
“MSPs are already stepping into this role for nearly half of their customers, creating a significant opportunity to deepen relationships and develop new, higher-value services. The challenge now is delivering that leadership consistently and efficiently across a growing customer base,” Barlow added.
The report also found that compliance has become a significant part of the services provided by MSPs. Nearly all surveyed MSPs, or 99%, provide at least one cybersecurity compliance service, while 58% offer full compliance programme management. However, only 6% provide the full range of compliance services covered by the research.
MSPs estimated that a single, unified platform for managing and reporting customer security posture and compliance could save them 53% of the time spent on these activities. Meanwhile, 81% said such a platform could reduce the time required by more than 30%.
Barlow said MSPs would need to address operational complexity as they take on broader cybersecurity responsibilities.
“MSPs have an opportunity to become indispensable strategic partners to their customers but scaling that role requires a more unified operating model,” he said.
“Bringing security posture, compliance management and reporting together can help MSPs spend less time manually consolidating information and more time helping customers reduce risk, strengthen resilience and make informed cybersecurity decisions.”