Sophos CISO Advantage uses AI to prioritize security fixes

Sophos CISO Advantage uses AI to prioritize security fixes

Sophos has released Sophos CISO Advantage, a service that uses agentic AI to link day-to-day security operations with longer-term security strategy. The goal is to tell businesses where their cyber risk lies, which fixes to fund first, and whether things are getting better over time.

The company says the output is written in plain language so that business leaders, not only security staff, can understand it, approve budgets and act on it. Sophos describes the offering as a new market category.

From security data to a roadmap

CISO Advantage assesses an organization's environment and maps its controls against established frameworks. These include NIST CSF (the US National Institute of Standards and Technology's Cybersecurity Framework), CIS v8, Cyber Essentials Plus (a UK certification scheme), and NCSC CAF, the Cyber Assessment Framework published by the UK's National Cyber Security Centre.

The results become a prioritized roadmap tied to budget. It shows what to fix first, what each fix costs, and why it matters to the business. Sophos says the AI can do this at a speed and scale that human experts working alone cannot match.

The tool is part of Sophos Fusion. As a result, assessments draw on live threat intelligence and on data from more than 625,000 organizations that Sophos protects, instead of relying on generic benchmarks.

A shortage of security leaders

Sophos frames the launch as a response to a talent gap. It cites the 2026 CISO Report, which estimates that about 35,000 chief information security officers (CISOs) serve 359 million businesses worldwide. That works out to roughly one CISO for every 10,000 companies.

The company's own 2026 MSP Perspectives Report found that, on average, 46% of customers now expect their managed service provider (MSP) to act as their CISO. 84% of MSPs expect demand for these services to grow over the next year.

Organizations without a CISO often lack the skills to assess risk and build a strategy. Those that have one face growing pressure to prove that controls work and to show progress to boards, regulators and insurers. According to Sophos, the average CISO tenure is 18 to 26 months, and 75% are thinking about changing jobs.

Sophos also points out that global information security spending is expected to reach $240 billion in 2026. Yet many organizations still track risk with disconnected assessments, spreadsheets and point products, which makes it hard to measure progress or justify investments.

"Good security strategy has always required expertise that's too scarce to scale, so it's stayed a luxury only the largest enterprises could afford," said Rob Harrison, SVP of Product Management at Sophos. "We built it around the question every board is now asking its security team: are we safer than we were last quarter, and can you prove it?"

Three ways to run it

Sophos says the product supports three approaches:

  • an internal team runs the program and uses the tool as its system of record
  • an MSP sets up the program first, and the organization later takes it in-house
  • a baseline assessment leads into a continuous managed service delivered fully by a partner

For MSPs already working as the de facto security lead for customers, the company pitches it as a way to turn that role into a structured and billable service.

Phil Harris, Research Director for Governance, Risk and Compliance Solutions at IDC, said security leaders need a system that shows "where they stand" and how their posture improves. "There are too many tools out there that track activity without any insight," he said.

Our Take

The launch fits a wider shift toward agentic AI in security tooling, from AI-driven SOC investigations to automated risk planning. Sophos is aiming higher up the chain, at strategy and board reporting rather than alert triage.

The talent numbers are hard to ignore, and they echo concerns about how AI is reshaping security jobs. For smaller firms, a tool like this could make structured risk planning reachable for the first time. Still, an AI-built roadmap is only as good as the data behind it and the people who review it.

It is worth watching whether boards, insurers and regulators accept AI-generated progress reports as credible evidence. Recent findings that many firms feel unready for AI threats suggest the demand is there.