There is one chief information security officer for roughly every 10,000 organisations on earth. Not in a single sector. Not in one country. Everywhere.
That figure comes from Sophos’s 2026 CISO Report, which puts the global count at around 35,000 CISOs serving an estimated 359 million businesses. Sophos published the report on 1 October 2026 and, on the same day, launched a product built to address exactly the gap the report describes: Sophos CISO Advantage.
The data and the product arrived together, two days before this piece. That simultaneity is the news, because it lets a vendor’s claims be weighed against independently structured workforce data in the same cycle.
Here is what the numbers show about how large the security leadership gap actually is, what it costs the organisations sitting inside it, and what this new class of AI-driven virtual CISO tooling can and cannot deliver.
One CISO for every 10,000 organisations: the numbers behind a leadership vacuum
Start with the arithmetic. 35,000 CISOs. 359 million businesses. That is one dedicated security leader for roughly every 10,000 organisations, according to the Sophos 2026 CISO Report.
1 CISO per ~10,000 organisations. The overwhelming majority of businesses have no dedicated security leadership at all.
Now layer in the broader workforce picture. The ISC2 2024 Cybersecurity Workforce Study, published in October 2024, estimated the world needs roughly 4.8 million additional cybersecurity professionals to adequately secure organisations. Across all roles, 90% of organisations reported skills shortages within their cyber teams.
The problem is not that the gap is large. It is that the gap is accelerating while supply sits still.
ISC2 found workforce headcount grew by about 0.1% year-on-year, effectively flat. Over the same period, the gap itself widened by roughly 19%. Demand is climbing nearly twenty times faster than the pool of people available to meet it.
The ISC2 workforce data sits inside a broader structural problem: cybersecurity skills shortages across all security roles grew at fifteen percentage points in a single year, a rate that makes the CISO deficit look like one symptom of a much larger staffing crisis accelerating throughout the industry.
| Metric | Figure | Source | Year |
|---|---|---|---|
| Global CISO-to-business ratio | 1 per ~10,000 | Sophos 2026 CISO Report | 2026 |
| Additional cyber professionals needed | ~4.8 million | ISC2 Workforce Study | 2024 |
| Workforce gap year-on-year growth | ~19% | ISC2 Workforce Study | 2024 |
| Workforce headcount growth | ~0.1% | ISC2 Workforce Study | 2024 |
That gap between 19% and 0.1% tells you something important. This is not a shortfall that normal hiring cycles close. The distance between where organisations are and where they need to be on security leadership is widening every year, not narrowing. If your organisation lacks a dedicated CISO, you are not an exception. You are the rule.
When big ASX news breaks, our subscribers know first
What the gap costs: risks that accumulate when no one owns security strategy
Numbers on a page are one thing. The cost shows up when nobody owns the security strategy.
Without CISO-level leadership, controls tend to be assembled piecemeal rather than validated as a system. Detection and response slow down because no one coordinates them. Sophos frames the practical shortfall bluntly: organisations without a CISO lack the skillset and resources to assess risk, build a coherent strategy, prioritise controls, invest appropriately, or demonstrate their posture to boards, regulators, and insurers.
Organisations without a CISO lack the skillset and resources to assess risk, build a coherent strategy, prioritise controls, invest appropriately, or demonstrate their posture to boards, regulators, and insurers.
The documented consequences compound in a predictable sequence:
- Fragmented or ad hoc controls that are never systematically validated
- Slower detection and response when an incident hits
- Higher regulatory and legal exposure after a breach
- Greater financial loss and reputational damage from uncoordinated crisis handling
Then there is a finding that reframes the whole problem. ISC2 reported that, for the first time, organisations cited lack of budget rather than lack of qualified talent as the primary cause of staffing shortages.
Security budget pressures were already forcing difficult trade-offs before this product launched: over 100 companies including Alphabet, Microsoft, and OpenAI signed a joint letter in August 2026 warning that AI-enabled attacks had risen 89% year-on-year while most enterprise defences had not kept pace.
That shift matters. It means many organisations understand the risk and know the people exist, but cannot fund the leadership. For you, that reframes the bottleneck entirely: this is an affordability gap, not a discovery gap, which means the solutions worth watching are the ones that lower the cost of accessing security leadership.
The market has already started filling the gap informally. Sophos’s 2026 MSP Perspectives Report found that roughly 46% of customers currently rely on their managed service provider (MSP) to fulfil CISO responsibilities, and 84% of MSPs expect that demand to grow over the next 12 months.
Hiring does not cleanly solve it either. The Sophos CISO Report shows that three-quarters of CISOs are actively weighing a move to a new role, and that most stay in post for somewhere between 18 and 26 months before leaving. Even organisations that win the hire often lose the leader before a strategy matures.
What Sophos CISO Advantage actually does, and how it is delivered
So what did Sophos actually ship on 1 October 2026?
CISO Advantage reached general availability that day, rolling out first across North America, the UK, and the rest of Europe, with global availability expected before the close of 2026. Sophos describes it as an agentic AI-enabled product, meaning the software can carry out multi-step analytic work with limited human prompting, designed to connect day-to-day security operations to board-level security strategy.
The functional scope covers six core capabilities:
- Organisation-specific security assessments tailored to each environment and threat profile
- Mapping of controls against established frameworks, including NIST CSF, CIS Controls v8, Cyber Essentials Plus, and NCSC CAF
- Continuous control validation
- Compliance mapping
- Peer benchmarking
- A prioritised remediation roadmap, sequenced by business impact and cost, with the financial case for each action set out clearly
The product runs on Sophos Fusion, which the company calls an AI-Native Cybersecurity Defense System. The differentiator Sophos leans on hardest is the data behind the assessments: rather than relying on generic industry benchmarks, the platform pulls from real-time threat intelligence gathered across the more than 625,000 organisations that Sophos actively protects.
That distinction is worth sitting with. An assessment grounded in 625,000 real environments reflects how threats actually behave in the wild. A framework checklist completed against self-reported controls reflects only how an organisation believes it is configured. For a buyer, those are structurally different products wearing similar labels.
The offence-defence asymmetry driving vendor investment in this space is structural rather than cyclical: Palo Alto Networks demonstrated that AI scanning can compress years of vulnerability discovery into weeks, fundamentally changing the threat baseline that any security leadership product, human or AI-augmented, must now be assessed against.
Deployment and pricing options
Sophos offers three ways to run it:
- Fully in-house, managed by the customer directly
- MSP-assisted transition, where a partner helps the customer move toward in-house management
- Continuous managed service, delivered entirely through a partner
Pricing follows two structures: an annual term licence for customers buying directly, and a monthly subscription via the MSP Flex programme for managed service providers. Partner materials position it as an assessment-led entry point that MSPs can bundle into their virtual CISO offerings. A more advanced enterprise edition, CISO Advantage Plus, is projected for 2027.
The open questions AI-driven vCISO tools have not yet answered
A product that promises CISO-level guidance at scale deserves CISO-level scrutiny. The questions below apply to any AI-augmented virtual CISO offering, not Sophos specifically, and they are drawn from guidance published before 2024 by bodies including NIST and ENISA.
Four concerns recur:
- Accountability and liability: When an AI-generated recommendation shapes a board-level risk decision, it is not always clear where responsibility sits if that recommendation later proves inadequate.
- Transparency and explainability: Tools informing security strategy must meet audit and regulatory expectations for explaining how they reached a conclusion, which not all AI systems satisfy.
- Data trust: Sensitive operational telemetry has to be handled, stored, and potentially used for model training, raising privacy and competitive sensitivity questions.
- Over-automation risk: Heavy reliance on AI outputs can obscure the contextual judgment an experienced CISO brings to trade-offs between security, compliance, and business priorities.
Sophos’s answer to these concerns is the human layer. Its stated design intent is that agentic AI handles the analytic and evidence-collection work, while human experts, delivered through the MSP partner network, interpret the outputs and make the decisions.
Agentic AI handles the analytic and evidence-collection work; human experts interpret outputs and drive decisions.
Channel Insider, in its 1 October 2026 coverage, characterised CISO Advantage as a tool that augments rather than replaces human advisory roles. That framing is reasonable, but it does not dissolve the accountability question. It transfers it.
The question that matters most to a board or an insurer is the first one on the list. When an AI-informed recommendation shapes a security investment that later proves inadequate, you need to know, before deployment, where responsibility sits and whether your MSP agreement states it explicitly. As of publication, no named analyst critiques of the product specifically had surfaced, which means the evaluation falls to buyers rather than being pre-packaged by the market.
Whether AI fills the CISO gap depends on what the question actually is
Return to the arithmetic that opened this piece. 359 million businesses. 35,000 CISOs. A gap widening at roughly 19% a year. No plausible near-term scenario closes that through human hiring alone, so some form of scaled, productised security leadership is not optional for most of the market. It is arriving.
Where AI-augmented tools are strong is the structured layer of CISO work: assessments, framework mapping, continuous validation, prioritised roadmaps. Where they are less complete is the contextual, liability-bearing, politically complex dimension of senior security leadership, the part that lives in human judgment and relationships.
That means the useful question is not “does this replace a CISO?” The sharper question is: “does this give us a structured, evidence-based security programme that our board and our insurer can actually evaluate?” If the answer is yes, the accountability gap becomes a procurement and contracting problem to solve, not a reason to walk away.
The forward signal is clear enough. With 84% of MSPs expecting CISO-service demand to grow over the next 12 months and CISO Advantage rolling out regionally ahead of global availability before year-end, the shift toward productised security leadership is already underway. The decision in front of you is whether a given tool’s delivery model fits your own governance and accountability requirements.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.

