ZeroHour
Help Net Securitypublished ()ingested Anamarija Pogorelec

MSPs say nearly half their customers rely on them for CISO services

infoIndustryimportance 12
AI summary · glm-5.3

Sophos survey finds MSPs act as CISOs for an average 46% of customers, mostly with partial compliance offerings and fragmented manual reporting.

A Sophos survey found MSPs estimate that 46% of their customers rely on them to act as CISOs, and most providers deliver only four to six of seven measured compliance services. More than half say they manage customers' full compliance programs, while compliance requirements influence roughly half of customers' security purchases. Nearly nine in ten providers use software, but most juggle multiple tools that cannot feed a central reporting platform, forcing staff to combine data manually. Providers estimated a unified platform would cut time spent on posture, compliance and reporting by about half; Sophos sells CISO Advantage via its Sophos Fusion system for this work.

  • MSPs estimate 46% of customers rely on them as de facto CISOs
  • Most providers deliver only four to six of seven measured compliance services
  • 55% partially automate posture reporting and still do some manually
  • Providers expect CISO-type work to grow and estimate unified platform halves time
  • Sophos sells CISO Advantage through Sophos Fusion targeting this need
Full article429 words · extracted from helpnetsecurity.com · click to collapse

MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools.

MSP CISO services

Most providers expect this work to grow. For many of those customers, the MSP is the closest thing they have to a security leader.

Most compliance offerings are partial

Nearly every provider does some compliance work. Providers also estimate that compliance requirements influence about half of their customers’ security purchases. Sophos measured seven services, from identifying which regulations apply to managing a customer’s whole compliance program, and most providers deliver four to six of them.

More than half of all providers say they manage customers’ full compliance programs, yet about one in ten of those also delivers the other six services. Sophos says some of that oversight may amount to coordinating work that customers or outside specialists perform.

The providers still feel good about the work. Ninety-five percent say they are confident they can track compliance across many customers, though a third call themselves completely confident.

Reports still take hand work

Nearly nine in ten providers use software for this work, but more of them juggle several tools than rely on one. Sophos says many of those tools cannot feed a central reporting platform, which leaves staff to combine data by hand.

Staff feel that most when they build security posture reports, the summaries that tell a customer where its security stands and what to fix. About a third of providers produce those reports through a fully automated process. A larger group, 55%, has automated part of the job and still does some of it manually.

Providers think one unified platform would help. On average, they estimated it would cut the time they spend on posture, compliance management and reporting by about half. Providers already running full compliance programs expected more savings than those with no plans to offer that service. Those figures are guesses about a hypothetical system. Sophos, which paid for the survey, sells a service aimed at this work, CISO Advantage, delivered through its Sophos Fusion system.

“MSPs have an opportunity to become indispensable strategic partners to their customers, but scaling that role requires a more unified operating model,” said Scott Barlow, VP and chief evangelist at Sophos. “Bringing security posture, compliance management and reporting together can help MSPs spend less time manually consolidating information and more time helping customers reduce risk, strengthen resilience and make informed cybersecurity decisions.”

Download: eBook: Identity-First Threat Intelligence

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/16/msp-ciso-services-compliance/