PropRecChannel
HomeInsightsMSPs are becoming the CISO. Who is going to do the work?

MSPs are becoming the CISO. Who is going to do the work?

New research from Cisco and Sophos shows partners moving fast into advisory, AI security and virtual CISO services. The opportunity is real. The constraint is people.

Two pieces of research published in September point in the same direction. Customers are handing more of their security thinking, not just their security tools, to partners.

Sophos's 2026 MSP Perspectives report, covered by MicroScope, found that MSPs now act as chief information security officer for around 46% of their customers, and 84% expect demand for those CISO services to rise. A week later, Cisco's 2026 global AI partner study, also reported by MicroScope, showed consulting and advisory services leaping from 12% to 50% as a leading growth opportunity for partners, the largest increase in the study.

What it means for talent

The work is shifting from tools to judgement

Running a firewall or an endpoint platform is a technical skill. Acting as someone's CISO is different: it means advising a board on risk, owning a compliance position, and making calls that carry consequences. The Sophos findings show the confidence gap clearly. Only about a third of MSPs say they are completely confident they can deliver continuous compliance.

That gap is a people problem. Virtual CISOs, governance, risk and compliance consultants, and security architects who can explain things to non-technical leaders are a different profile from the engineers most MSPs have spent years hiring.

AI adds a skill nobody has much of yet

Cisco found that for a quarter of its partners, AI already accounts for more than half of revenue, and 55% expect it to within five years. Yet multi-agent orchestration ranked as the weakest area measured, across customer readiness, partner capability, knowledge and hands-on experience. Securing agentic AI is newer still.

That combination, fast-growing demand and a thin pool of experienced people, is exactly the condition that pushes salaries up. The people who can advise credibly on AI risk will be among the most sought after in the channel over the next two years.

Training is lagging behind

MicroScope's report also quotes ISACA's 2026 State of Cyber research, with ISACA's Chris Dimitriadis pointing to "a distinct lack of investment in the workforce, training and resources". Businesses that build their own capability, rather than relying entirely on the external market, will have a real advantage.

What to do now

Decide what you are actually selling. A vCISO service needs senior advisory people, not just more analysts. Define the roles before you hire for them.

Hire one senior anchor, then build around them. A credible security leader who has sat in the CISO seat attracts and develops the next layer of talent. Hiring five mid-level engineers and hoping one grows into it rarely works.

Grow your own. Identify engineers with the communication skills to move into advisory work, and fund the certifications and exposure to get them there. It is slower than hiring, but it's cheaper and they're more likely to stay.

Price the service for the people it needs. If you are pricing vCISO services on engineer day rates, your margins will not survive the salaries.

Building an advisory or AI security practice? PropRec recruits security leaders and consultants for MSPs and resellers, and can help you build your own talent team. Book a call to talk it through.

Sources

What this means for you

Get our view on your team.

Tell us a little about your business and a senior consultant will come back to you the same working day, in confidence.

Or book a call with Chris

We only use your details to reply, and treat everything you share in confidence. See our privacy policy.