top of page

Most vCISO Services Are Sold by Your Tool Vendor

  • 6 days ago
  • 12 min read
msp vs vciso services

By Yonatan Hoorizadeh, CISSP, CISM, CRISC, AAISM

Published By: Purple Shield Security

Published: August 26, 2026

Last updated: August 26, 2026


Two thirds of managed service providers now sell vCISO services, up from 21% a year earlier, according to Cynomi's 2025 State of the vCISO Report. That creates a structural conflict: one firm sets your security priorities, assesses your risk, and sells the remediation. Independence is a control, not a marketing claim.

What changed in the vCISO market?


Adoption of vCISO offerings among managed service providers (MSPs) and managed security service providers (MSSPs) climbed from 21% in 2024 to 67% in 2025, a 319% year-over-year increase, according to Cynomi's 2025 State of the vCISO Report. The survey covered 200 senior leaders at North American service providers. Work that independent security executives used to do is now, in most cases, a channel product.


The same Cynomi research found another 50% of non-adopters planning to launch a vCISO offering before the end of 2025, and a further 27% targeting 2026. Combined high and moderate client demand reached 96% of providers surveyed. On the supply side, the category has been close to fully absorbed by the managed services channel in roughly twenty-four months.


Platform tooling made that absorption possible. AI-assisted vCISO platforms generate risk registers, compliance gap reports, and board decks from structured inputs, and Cynomi reported an average 68% reduction in manual vCISO workload among providers using them, with 42% of respondents reporting reductions between 81% and 100%. A generalist can now produce an executive-looking deliverable without having run a security program.


Cynomi's own reporting is unusually direct about why providers add the service. Its 2023 report named the ability to upsell more products and services as the single leading benefit of a vCISO offering, cited by 44% of respondents, and the 2025 edition found 41% reporting increased upsell opportunities. Cynomi co-founder and CEO David Primor described the broader shift as cybersecurity being "no longer just about protection, it's a business growth driver."


Worth being precise about the source. Cynomi sells the platform that made this shift economical, and the report exists to encourage MSPs to adopt the model. These are not a critic's numbers. They are the strongest available data on how vCISO services are delivered in 2026, published by a company with every reason to present the trend favorably.


Why does it matter who your vCISO works for?


A vCISO's real job is deciding what a company will not spend money on. Every prioritized roadmap is a resource allocation decision, and most of those decisions are about what to skip, defer, consolidate, or cancel. When a provider's revenue moves with the answer, the recommendation stops functioning as advice and starts functioning as a proposal.


Three distinct roles used to sit in three different companies. The operator runs your systems. The assessor grades your controls. The seller supplies your tools. Any two of those can coexist under reasonable safeguards. All three inside one contract removes every check that made the arrangement workable.


None of this requires bad faith, and most MSPs delivering vCISO services are competent and well intentioned. Incentives do not need bad faith to bend an outcome. No auditor has ever explained independence rules by saying auditors are dishonest. The rules exist because pressure applied consistently over years moves judgment in a predictable direction, and nobody involved notices it happening.


What goes wrong when the same MSP does your vCISO work and your risk assessment?


Bundling security leadership and risk assessment services into one MSP contract means the firm that operates your controls also decides whether those controls are adequate, sets the scope of the review, writes the findings, and prices the remediation. Six specific failures follow from that structure. Each one tends to surface later as an audit exception, an insurance dispute, or an incident nobody caught early.


The assessment grades the assessor's own work


If your MSP manages firewalls, patching, backups, identity, and endpoint tooling, a large share of any honest risk assessment is a review of that MSP's own delivery quality. No competent auditor would accept the equivalent arrangement in a financial context. In security it gets sold as convenience. The practical result is a report that is thorough about user behavior and password policy, and noticeably thin about configuration, patch latency, and privileged access inside the systems the provider runs.


Scope quietly forms around the provider's stack


Assessments are won and lost at scoping, which happens before anyone writes a finding. When the assessor operates the environment, the boundary tends to settle around what the provider already monitors. Four areas fall outside that line most often: unsanctioned SaaS, unmanaged contractor and BYOD endpoints, legacy applications the provider never onboarded, and the provider's own remote access and RMM tooling. A client reading the finished report cannot see any of it, because exclusions are rarely written down.


The finding and the invoice come from the same place


Every assessment produces a remediation plan. When the party that wrote the finding also quotes the fix, the plan converges on products that party already resells. The tell is a roadmap where all five top-priority items have a SKU attached. Real security roadmaps are full of unglamorous work with nothing to buy: decommissioning a forgotten system, revoking standing admin access, fixing a joiner-mover-leaver process, getting a data flow written down for the first time.


Risk acceptance loses its second signature


Accepting a risk requires two parties: someone who states the risk plainly and someone with authority who accepts it in writing. That separation is the entire mechanism. In a bundled arrangement, the party stating the risk is also the party whose contract could be affected by how forcefully it gets stated, and the acceptance frequently never gets documented at all. When a regulator, an insurer, or a plaintiff's counsel asks who decided a given risk was tolerable and on what basis, the answer has to be a name and a date.


Incident response becomes self-investigation


An incident that begins in a managed system puts the provider in the position of investigating its own operations and writing the report that assigns cause. Root cause analysis under those conditions bends toward attacker sophistication and away from a missed patch, an over-permissioned service account, or an alert that fired at 2 a.m. and was closed without review. Independent incident response earns its cost precisely at that moment, which is the worst possible time to discover you do not have it.


One compromise takes out operations and oversight together


CISA, the FBI, the NSA, and the national cyber agencies of the United Kingdom, Australia, Canada, and New Zealand issued joint advisory AA22-131A specifically because attackers target MSPs to exploit provider-customer trust relationships. When one provider runs both your infrastructure and your security oversight, a compromise of that provider removes both at once. The advisory's own guidance points straight at the contract, telling organizations to ensure MSP-customer agreements "transparently identify ownership of ICT security roles and responsibilities."


Every other assurance discipline already settled this. Why hasn't security?


Independence is not a philosophical position in adjacent fields. It is a rule with a citation. Defense contracting, New York financial services regulation, and now California privacy law all restrict the same party from building a program and then attesting to it. General vCISO and risk assessment work sits in the one corner of the market where no such rule exists, which is exactly why the buyer has to impose it by contract.


In the Cybersecurity Maturity Model Certification (CMMC) program, a Certified Third-Party Assessment Organization (C3PAO) cannot assess an organization it has provided consulting, advisory, or implementation services to. The prohibition is codified in the CMMC program requirements at 32 CFR Part 170 and enforced through the Cyber AB Code of Professional Conduct, with assessment team members signing conflict-of-interest attestations before an engagement begins. A firm may offer both services. It may not offer both to the same client.


New York wrote the definition into regulation. Under 23 NYCRR 500.1, an independent audit is one performed by internal or external auditors whose decisions the audited entity, its owners, managers, and employees cannot influence. Class A companies under the NYDFS cybersecurity regulation must conduct those audits at a frequency set by their own risk assessment.


Notice what none of these regimes did. None of them solved the conflict by requiring disclosure. Each one barred the conflicted party from doing the work. That distinction matters when a provider tells you the arrangement is fine because they are upfront about it. Disclosure is the remedy for a small conflict. Separation is what every regulator that has actually written a rule on this chose instead.


What do regulators require when a third party is your CISO?


Regulators permit outsourced security leadership and attach a condition most buyers never implement. Both the FTC Safeguards Rule and the NYDFS cybersecurity regulation allow an outside firm to hold the role, then require the client to retain compliance responsibility and name a senior person of its own to direct and oversee that outside individual.


Under the FTC Safeguards Rule at 16 CFR 314.4(a), the Qualified Individual responsible for your information security program may be employed by you, an affiliate, or a service provider. Where that role sits with a service provider or affiliate, the rule requires you to retain responsibility for compliance, designate a senior member of your own personnel responsible for direction and oversight of the Qualified Individual, and require the provider to maintain an information security program that protects you. The FTC's plain-language business guidance compresses all of it into one line: "the buck still stops with you."


New York uses nearly identical construction. 23 NYCRR 500.4(a) permits the CISO to be employed by the covered entity, an affiliate, or a third-party service provider, and where a third party holds the role, the covered entity must retain responsibility for compliance, designate a senior member of its own personnel to direct and oversee that provider, and require the provider to maintain a compliant cybersecurity program.


The condition is the part that breaks in practice. In a bundled MSP arrangement, the designated internal overseer is frequently an office manager, controller, or operations lead with no security background who defers entirely to the same provider they were appointed to oversee. That is oversight on paper. Under examination or in discovery, "our MSP handled it" is not a defensible answer, because both rules specifically anticipated and prohibited that outcome.


There is a sharper version of this test for NYDFS covered entities. The annual Certification of Material Compliance is signed by a senior officer and the CISO. If an outsourced CISO signs that certification for you, it is fair to ask whether that person has ever reviewed the underlying evidence independently of the team that produced it.


When is an MSP-delivered vCISO actually the right call?


Often, and pretending otherwise would be dishonest. For a company with no regulated data, no audit obligation, no enterprise security questionnaires, and a small environment, an MSP-delivered vCISO is affordable, fast, and enormously better than no security leadership at all. The structure becomes a liability at identifiable trigger points rather than at a headcount number.


Separate the roles once any one of the following is true:


  • You are a HIPAA covered entity or business associate.

  • You are a non-bank financial institution under the FTC Safeguards Rule at 16 CFR Part 314, which reaches mortgage brokers, auto dealers, tax preparers, collection agencies, and investment advisers not registered with the SEC.

  • You are a covered entity under 23 NYCRR Part 500.

  • You meet the CPPA cybersecurity audit thresholds described below.

  • You are pursuing SOC 2, ISO 27001, or CMMC certification.

  • A cyber insurer, enterprise customer, or acquirer has started asking for evidence rather than assurances.

  • Your MSP manages more than roughly half of your production environment, which makes a self-assessment structurally unable to cover the majority of your risk.


A middle path exists and works well. Keep the MSP for operations and place independent security leadership above it. That arrangement is where most regulated mid-market firms end up, and it is what gives the senior person named under the FTC and NYDFS oversight condition someone to rely on who is not the party being overseen.


How do you test a vCISO provider's independence in one call?


Six questions will do it, and the answers belong in the engagement letter rather than the sales call. A provider who answers all six cleanly is worth hiring whether they are independent or attached to an MSP. A provider who gets vague on the first, third, or sixth question has told you something useful.


  1. Do you earn anything if I buy what you recommend? The honest answers are yes or no. Follow up specifically on resale margin, referral fees, vendor market development funds, and bundled licensing. "We are vendor-agnostic" is a positioning statement, not an answer.

  2. Will you assess controls you operate, and what is your written policy when the answer is yes? A serious provider already has that policy. "We disclose it" is a weaker answer than "we do not do it."

  3. Who signs the risk acceptance when I decline a recommendation? You want a named role on your side and a documented format. If nobody signs anything, risk acceptance is not actually happening in your company.

  4. Is the person on my board deck the person doing the work? Named-operator engagements and bench models are both legitimate. Selling one and delivering the other is not.

  5. Have you ever recommended cancelling a tool you sell, and can you show me a redacted example? Nothing separates advisors from resellers faster than this question.

  6. If an incident begins in a system you manage, who writes the post-incident report? The right answer names somebody other than the party under review.


For transparency about my own position: Purple Shield Security holds no MSP contracts, resells no products, and takes no vendor referral fees. That is a structural choice rather than a virtue. It keeps recommendations like "spend less here" and "cancel this tool" available as real outcomes.


Does any of this look different for a Los Angeles company?


California now requires auditor independence by regulation, which most states do not. The California Privacy Protection Agency's cybersecurity audit rules took effect on January 1, 2026 at Cal. Code Regs. tit. 11, sections 7120 through 7124, and require covered businesses to use a qualified, objective, and independent professional auditor applying professional auditing standards. The rules add that audit findings cannot rely primarily on assertions or attestations from the business's own management.


Coverage turns on data volume and revenue rather than industry. According to a January 2026 analysis by Ropes & Gray, a business is covered if it derives 50% or more of annual revenue from selling or sharing consumers' personal information, or if it meets the CCPA revenue threshold of roughly $26 million adjusted for inflation and processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers.


Certification deadlines phase in by revenue: April 1, 2028 for businesses above $100 million, April 1, 2029 for businesses between $50 million and $100 million, and April 1, 2030 for businesses under $50 million. Each certification reports on a twelve-month audit period that precedes the filing date, so the governance structure being graded is largely the one a company operates over the next two to three years, not the one it assembles the month before filing.


One requirement in the CPPA rules deserves particular attention from anyone buying vCISO services in Los Angeles. The audit report must include a signed statement from the highest-ranking auditor certifying that the review was independent, objective, and impartial. A company whose security program, risk assessment, and tooling all arrive on one invoice will struggle to obtain that signature from anyone willing to stand behind it. For Los Angeles law firms, medical groups, entertainment vendors, and financial services firms, that is the practical argument for separating operations from oversight now instead of in 2029.


Frequently asked questions


Can my MSP legally be my vCISO?


Yes. No US regulation prohibits it, and two of the most prescriptive rules explicitly allow it. The FTC Safeguards Rule at 16 CFR 314.4(a) permits the Qualified Individual to be employed by a service provider, and 23 NYCRR 500.4(a) permits the same for the CISO role. Both then require you to retain responsibility for compliance and designate a senior member of your own personnel to direct and oversee that provider. The legal question is settled. The governance question is the one worth arguing about.


Is there a rule against the same firm building my security program and assessing it?


In CMMC, yes. A C3PAO cannot assess an organization it has provided consulting, advisory, or implementation services to, under the CMMC program requirements at 32 CFR Part 170. In California, the CPPA cybersecurity audit rules require a qualified, objective, and independent auditor whose findings do not rest primarily on management assertions. Outside those regimes, no rule governs general vCISO and risk assessment work, so the separation has to be written into your contract instead.


What is the difference between CISO as a service and an MSP security bundle?


CISO as a service is another name for vCISO services and fractional CISO services: a senior security executive who owns strategy, risk decisions, compliance, and board reporting on a part-time basis. An MSP security bundle is operational delivery, meaning managed endpoint tooling, patching, monitoring, backups, and alerting. The two are complementary and most mid-market firms need both. Problems begin when one contract silently covers both and nobody outside the provider ever reviews the result.


Does hiring an independent vCISO mean firing my MSP?


No, and it usually should not. The common arrangement for regulated mid-market firms keeps the MSP running operations and places independent security leadership above it. An outside vCISO does not by itself satisfy the FTC requirement, which asks for a senior member of your own personnel to direct and oversee the arrangement. What it does is make that person's oversight real, because they finally have someone advising them who is not the party being overseen.


What should I expect to pay for independence?


Independent engagements are typically priced as a fixed monthly retainer scoped to your stage, rather than folded into a per-seat managed services fee, which makes the cost visible instead of buried. The comparison that matters is not one retainer against another. It is the retainer against the remediation spend a conflicted roadmap tends to generate, plus the audit exceptions, questionnaire delays, and insurance friction that follow a self-assessed program.


If your security program, your risk assessment, and your tooling all arrive on the same invoice, the useful first step costs nothing: write down which of the three roles sits where, and who signs when you decline a recommendation. Purple Shield Security provides independent vCISO services and fractional CISO services in Los Angeles and works alongside existing MSPs rather than replacing them, with no products to sell and no referral fees attached to the advice. If you want a second set of eyes on whether your current arrangement holds up to an insurer, an auditor, or a regulator, that is a short conversation.

 
 
bottom of page