There’s a pattern emerging across MSP practices of all sizes. Clients who have relied on their managed service provider for IT operations are now bringing a different category of question to the table: questions about security programs, compliance frameworks, cyber insurance requirements, and board-level risk reporting.
These aren’t IT questions. They’re security leadership questions. And most MSPs weren’t built to answer them.
That gap – between what MSPs were designed to do and what clients increasingly need – is where a lot of the industry’s current growing pains live. Understanding it clearly is the first step to navigating it well.
Why the Demand Is Shifting Now
Several converging forces are driving SMB clients toward their MSPs with security questions:
- Cyber insurance has gotten complicated. Underwriters have significantly tightened requirements over the past two years. Clients renewing policies are encountering detailed security questionnaires, mandatory controls, and in many cases, premium increases tied to gaps in their security posture. They need help interpreting requirements and demonstrating compliance, and they’re turning to whoever manages their IT.
- Federal contracting is trickling down. The Cybersecurity Maturity Model Certification (CMMC) framework, required for Department of Defense contractors, has a supply chain effect. Prime contractors are pushing compliance requirements to subcontractors, some of whom are small businesses with no security staff. Those businesses need guidance, documentation, and a path to certification.
- Boards are asking harder questions. After high-profile breaches in industries that once felt insulated, more business owners and boards are requesting internal reviews of their security programs. Often, those reviews reveal that what exists is informal, undocumented, or incomplete.
The common thread: each of these situations requires security expertise that goes beyond managing endpoints, patching systems, or monitoring alerts. They require someone who can assess risk, speak to frameworks, and help an organization build a defensible, documented security program.
The CISO Function — and Why Most SMBs Don’t Have One
A Chief Information Security Officer is responsible for an organization’s entire security posture: strategy, policy, risk management, compliance, incident response planning, and communication with leadership. It’s a senior executive role, and it commands a senior executive salary: typically $200,000–$300,000 annually for a full-time hire, before benefits and overhead.
For most SMBs, that’s simply not a realistic option. But the security leadership function doesn’t go away just because the budget doesn’t support a full-time hire. The need exists regardless.
This is the core problem the fractional CISO model was developed to address.
What Fractional CISO Engagement Actually Looks Like
A fractional CISO provides part-time, contracted security leadership to organizations that need the expertise without the full-time cost. The model varies in structure, but some common elements:
- Scope definition is critical. A good fractional engagement starts with clarity about what the organization actually needs. Is it a one-time assessment and documentation project? Ongoing advisory support? Help navigating a specific compliance framework? The scope should drive the engagement, not the other way around.
- It’s a strategic role, not a technical one. Fractional CISOs aren’t there to configure firewalls or manage your SIEM. They assess risk, develop policy, interpret frameworks, communicate with leadership, and ensure that the technical work your team is doing aligns with a documented security strategy. The distinction matters when setting client expectations.
- Documentation is often the primary deliverable. For many SMBs, the most immediate need is written evidence of a security program – policies, procedures, risk assessments, and control documentation – that can withstand scrutiny from an insurer, auditor, or regulator. That’s work that requires both security knowledge and the ability to translate it into clear, organized documentation.
- The engagement should connect to the MSP’s existing work. The most effective fractional CISO relationships don’t exist in isolation from the client’s managed service provider. They’re designed to complement what the MSP is already doing, providing the security strategy layer that makes the MSP’s technical work more coherent and defensible.

How MSPs Are Structuring Around This Gap
MSPs taking a deliberate approach to the security leadership question are generally pursuing one of three paths:
- Building internal capability. Some MSPs are investing in certifications (CISSP, CISM), hiring security-focused staff, or developing vCISO service offerings in-house. This works well for larger MSPs with the volume to support it and the clients who prefer a single-vendor relationship.
- Referral relationships. Other MSPs identify trusted security advisors or firms and refer clients directly when security leadership needs arise. This keeps the MSP’s core offering clean but risks the client relationship migrating if the referral partner becomes the primary trusted advisor.
- Co-delivery or white-label partnerships. A growing number of MSPs are partnering with fractional CISO providers in structured ways: co-delivering engagements or white-labeling security advisory services under their own brand. This allows the MSP to expand its offering without building the capability from scratch, while maintaining the client relationship.
Each model has tradeoffs. The right choice depends on your client mix, your team’s existing expertise, and how central you want security to be to your practice’s identity going forward.
Questions Worth Asking in Your Own Practice
Before deciding how to respond to this shift, it’s worth taking an honest look at where things stand:
- When a client brings a security question you can’t fully answer, what happens to that conversation?
- Do your clients understand the difference between what your managed services cover and what a security program requires?
- If a client had an incident tomorrow, could you help them demonstrate they had a reasonable security posture in place?
- Are you positioned as a strategic partner in your clients’ security decisions, or primarily as an operational vendor?
There are no universally right answers here, but the questions tend to surface where the gaps are.
If you’re thinking through how to approach the security leadership question, we’re happy to be a resource.
Additional Questions MSPs Should Be Asking
What is the difference between an MSP and a fractional CISO?
An MSP primarily manages and supports IT infrastructure, systems, and day-to-day operations. A fractional CISO focuses on security leadership, including risk management, compliance strategy, policy development, incident response planning, and executive-level guidance. While the two roles can work closely together, they solve different business problems.
Why are small and mid-sized businesses looking for vCISO or fractional CISO services?
Many SMBs are facing increased pressure from cyber insurance providers, compliance requirements, and customer security expectations. They need experienced security leadership but often cannot justify the cost of a full-time Chief Information Security Officer. Fractional and virtual CISO services provide strategic security expertise at a more manageable cost.
Can MSPs offer vCISO services without building a full internal security team?
Yes. Many MSPs partner with security consultants or fractional CISO providers through referral, co-delivery, or white-label arrangements. This allows MSPs to support client security needs without immediately investing in a large internal cybersecurity practice.




