How MSPs can bridge the security leadership gap

CISOs and SMBs are not a combination you often see. Not because SMBs don’t need security leadership. Regulatory pressure, cyber insurance requirements, and customer security questionnaires are making strategic security leadership a necessity. The challenge is cost.

A skilled CISO often commands a six-figure salary. For many small businesses, that investment is difficult to justify. As a result, the vCISO model has become an attractive way to close the gap. MSPs are increasingly well-positioned to fill that role.

The opportunity is growing quickly as more SMBs look for affordable ways to strengthen security, manage risk, and meet compliance requirements. The question is whether MSPs can deliver the strategic leadership those organizations need.

Technical visibility isn’t enough

Stanislav Kazanov, Head of GRC, Cybersecurity, and Sustainability at Innowise, a global software development and IT services firm, says MSPs already possess a key advantage: technical visibility.

“MSPs often have detailed visibility across endpoints, identity, cloud platforms, backups, networks, and user support,” he said. “They may already understand where the customer’s operational weaknesses and technology dependencies exist.”

However, Kazanov cautions that visibility alone does not make an MSP a vCISO.

“Technical visibility does not automatically create strategic leadership.”

That distinction is one Luke Irwin, CEO and Principal Consultant at Aegis Cybersecurity and a fractional CISO with CISSP, CISM, and ISSMP credentials, says MSPs consistently underestimate.

“In many cases, I have seen an existing Technical Account Manager, Service Delivery Manager, or salesperson given a new title and then expected to use the vCISO function to sell security licensing,” he said. “That is fundamentally different from providing genuine cybersecurity advisory services. Those services require understanding business objectives, assessing security posture and risks, developing strategy, and delivering independent recommendations.”

What separates a true vCISO from a title change?

Irwin stresses that organizations need experienced professionals in the role.

“By suitably experienced, I mean someone with at least a decade of relevant experience, regular exposure to boards and senior executives, and the ability to design and structure a cybersecurity strategy,” he said. “They must also have enough breadth of knowledge to provide advice tailored to the organization rather than just its technology stack.”

He also offers a practical test.

“Ideally, they should be covered by an appropriate professional indemnity policy. If an insurer is unwilling to underwrite the advice being provided, that is a useful indicator of the risk the MSP may be assuming.”

Curtis defines the role in operational terms.

“The vCISO should understand the business model, identify what could materially interrupt the organization, establish priorities, build the security roadmap, brief executives, and ensure risks have accountable owners,” he said.

“They should also help organizations prepare for difficult decisions during an incident. Those decisions include isolating systems, notifying customers, engaging law enforcement, or invoking business continuity arrangements.”

His measure of success is straightforward.

“The value is not measured by how many hours the vCISO spends in meetings. It is measured by whether the organization makes better risk decisions.”

Managing conflicts of interest

Both Curtis and Irwin warn MSPs to carefully manage potential conflicts of interest.

“If the same provider identifies the risk, recommends the product, sells the product, implements it, and then declares the risk resolved, the provider is effectively marking its own homework,” Curtis said.

That does not disqualify MSPs from offering vCISO services. However, Curtis says providers must establish clear boundaries.

“The advisory function needs a clear charter, transparent commercial boundaries, and evidence-based recommendations,” he said. “The vCISO should have direct access to the CEO, executive team, or board. They must also be free to recommend another provider’s solution when it is genuinely in the client’s best interest.”

Partnerships may be the smarter approach

For MSPs that lack the internal depth to deliver a true vCISO service, Irwin recommends a different model.

“For many MSPs, I believe the better model is partnership,” he said. “Rather than building every capability internally, MSPs can become Technical Services Partners. They can serve as the hub through which clients access IT, cybersecurity, BI, AI, and other specialist services.”

In this model, MSPs retain and strengthen client relationships while participating commercially in engagements.

“They become increasingly trusted because, when the client needs expertise outside the MSP’s core capability, they know someone who can help.”

Irwin warns that the alternative often creates unnecessary tension.

“The purpose of cybersecurity is not primarily to generate licensing revenue. Its purpose is to protect the organization.”

He also highlights a liability risk that many MSPs overlook.

“If an account manager, TAM, or service delivery manager with a newly applied vCISO title provides poor advice, the consequences can extend far beyond a dissatisfied client,” he said. “Following a major incident, both parties may examine who provided the advice, whether they were qualified to provide it, and whether the organization reasonably relied upon it.”

Curtis believes the value of a vCISO comes down to timely access to experienced judgment.

“A business may not need 40 hours of a CISO’s time every week, but it does need CISO-level judgment when the consequences are real,” he said. “A strong vCISO gives smaller organizations access to that judgment before a cyber incident turns an affordable advisory service into an unaffordable business crisis.”

Photo: DC Studio / Shutterstock

This post originally appeared on Smarter MSP.