Cybersecurity customers today need more than technology management. With just one Chief Information Security Officer (CISO) for every 10,000 organizations globally, many are looking for a partner who can help them manage risk, prioritize security investments, and build trust across the business. This persistent cybersecurity “strategy gap” creates an opening for MSPs to provide the direction and leadership those customers lack. Sophos’ 2026 MSP Perspectives Report highlights the opportunity for MSPs to step further into their role as cybersecurity leaders and turn strategic services into new revenue opportunities. It also examines the technical and operational barriers preventing many from doing so.
As Scott Barlow, VP, Chief Evangelist at Sophos, observes, “The partners that can bring clarity to complexity, helping their customers see where they stand, how they are improving, and where risk remains, will be best positioned to fill this leadership void.”
Key takeaways from the 2026 MSP Perspectives Report
- MSPs are the de facto CISO: 88% say at least 20% of their customers look to them to act as their CISO.
- That is set to increase: 84% of MSPs expect demand for CISO services to increase over the next 12 months.
- Compliance is driving customer security investment: 50% of customer purchasing decisions are influenced by regulatory compliance requirements.
- Automation still requires manual effort: While 86% of MSPs use automation for cybersecurity reporting, 55% still require manual processes to complete these activities.
- A different approach would change everything: 53% is the time saving available to MSPs if they had a single, unified platform for customer security posture and compliance activities.
What is next for MSPs?
MSPs are being asked to play a bigger role in their customers’ cybersecurity strategy. Beyond technology management, they have taken on the responsibility of assessing risk, guiding investment, managing compliance, reporting on maturity, and helping business leaders prioritize security tactics.
According to the report, MSPs estimate that 46% of their customers on average rely on them for this kind of cybersecurity leadership. This creates an opening for them to move beyond increasingly commoditized delivery services and build deeper, higher-value customer relationships.
This is not a temporary extension of the traditional MSP function, and stepping into their new role isn’t straightforward. However, it does create an opportunity to move beyond commoditized delivery services.

Operational constraints emerge from growing demand
Scaling strategic services requires MSPs to perform a wide range of additional services which demand more tools, workflows, data sources, and reporting processes. Teams may need to gather evidence, map controls to frameworks, reconcile data from different systems, and translate technical findings into business priorities. Meanwhile, customers are scrutinizing security spend more closely and expecting proof that investment is directly reducing cyber risk.
Most MSPs have introduced technology to support this work; 89% use at least one tool or platform to manage compliance or CISO-type activities. Meanwhile, reporting shows a similar pattern. 55% of MSPs still need manual effort to combine data, add context, and finalize their reports.

Although AI can relieve some of this pressure, particularly across repeatable activities such as evidence collection, assessment, analysis, reporting, and roadmapping, its effectiveness depends on its application. Simply adding another standalone AI tool risks creating further fragmentation.
The ultimate goal for MSPs is to find a way to consolidate and streamline these activities together. MSPs estimate that a single, fully unified platform for managing customer security posture, compliance, and reporting could reduce the time spent on this work by 53%. All but one MSP surveyed anticipated time savings, indicating the widespread scale of the efficiency opportunity.

These findings point to a clear requirement: MSPs need an AI-native system that makes all essential compliance service areas, plus ongoing program management, more repeatable across their customer base.
Helping customers take control of their security outcomes
Sophos CISO Advantage is a completely new way for MSPs to provide strategic cybersecurity at scale. By bringing analysis, assessment, reporting, and cost consolidation into a single, unified view, customers can reduce cyber risk, achieve compliance, and direct budget with greater efficiency and focus.
Delivered through Sophos Fusion, the Sophos AI-Native Cybersecurity Defense System, Sophos CISO Advantage helps transform the CISO role many MSPs already perform into a structured, scalable, and billable cyber program management service.

For MSPs, Sophos CISO Advantage is a path to commercialized cybersecurity leadership:
- Turning work that is often delivered informally into a structured, billable service
- Using AI-accelerated workflows to reduce manual effort, save time, and free up more resources for strategic activities
- Scaling MSP expertise across the customer base, with each assessment informing further customer investment
As more organizations look to their providers for CISO-level leadership, Sophos CISO Advantage is a differentiator, strengthening customer relationships and helping MSPs monetize the leadership role they perform every day.

