Sophos Exec: The ‘Cybersecurity Poverty Line’ And AI Security Gap
Scott Barlow, chief evangelist and global head of community at Sophos, tells MSPs at this week’s XChange August 2026 conference that AI is widening a cybersecurity divide, forcing partners to help customers cross what he calls the ‘cybersecurity poverty line’ before weak security capabilities leave them exposed.
For MSPs and security solution providers, the rise of AI is forcing a harder conversation about whether customers have the funding, expertise, operational capability and strategic influence needed to defend themselves in an increasingly complex threat landscape.
That’s the word from Scott Barlow, chief evangelist and global head of community at Sophos, the Oxfordshire, U.K.-based developer of network and endpoint cybersecurity, who told MSP attendees of this week’s XChange August 2026 conference in National City, Md., that many partners and their customers are not ready for AI’s impact on security.
The XChange conference is hosted by CRN parent company The Channel Company.
[Related: Cisco Execs To Partners: Cloud Control, AI Security Push Create New Monetization Openings]
Barlow used the concept of the “cybersecurity poverty line” to describe a threshold below which organizations can no longer reliably achieve good security outcomes. The issue, he said, is not defined by company size or security spending. Instead, it is a broader strategic capability gap that can affect organizations with too little money, insufficient expertise, limited ability to execute, or not enough influence over how security is implemented across their environments.
Barlow also warned that more security tools do not necessarily translate into stronger security. With Security Operations Centers (SOCs) and enterprises managing large numbers of consoles and products, he argued that complexity itself has become part of the problem. For partners, that means consolidation is not just a vendor talking point but a way to reclaim resources that can be redirected toward higher-value security work.
The shortage of CISO-level leadership further raises the stakes for MSPs, which Barlow said are increasingly being pushed into advisory roles even when customers may still view them primarily as technology operators. At the same time, AI is expanding the attack surface at a pace that is difficult for both partners and customers to govern. Barlow said MSPs and customers are moving at the same speed on AI adoption, a shift that makes it harder for partners to stay ahead of risk.
“It is a strategic security capabilities gap, and we see it every single day,” he said. “When we look at the number of CISOs that are out there today, there is one CISO for every 10,000 organizations. There are 359 million organizations and only about 35,000 CISOs, and that is half the number of people that actually attend a Taylor Swift concert.”
What Is The Cybersecurity Poverty Line?
Barlow framed the cybersecurity poverty line as a practical threshold where organizations, regardless of size or budget, can no longer consistently produce strong security outcomes. The issue is not simply a matter of whether a company has money, tools or a CISO but whether it has the right mix of funding, expertise, capability and influence to execute effectively, he said.
“If you can’t afford the tools, obviously you’re going to be below the cybersecurity poverty line,” he said. “Expertise? Even with the money, you need to be out there and able to go and implement it and use those tools really well. … We’ve seen a lot of capability with no money. You’re still below the line. A ton of money with zero capability is a huge issue as well. And then influence? Defense doesn’t end at the perimeter of your organization. A lot of organizations just don’t have the influence to go into that implementation.”
Tool Sprawl Isn’t The Same As Stronger Security
Barlow warned that piling more products into the security stack does not automatically improve protection. He pointed to the complexity facing SOCs and enterprise customers, including the number of consoles and tools they manage, and argued that consolidation can free up resources that partners now spend administering vendor programs.
Barlow said Sophos sees a lot of tools in IT environments today, with the average SOC managing 10.9 security consoles and the average enterprise organization using 45 tools, according to a study the company did.
“We actually did a study across the MSP base, about 800 partners, and we found that if you can consolidate from six down to one from a security product standpoint, you’re actually going to save 48 percent of the resources that you are implementing to go toward managing the vendor programs that are out there today,” he said.
The cybersecurity poverty line, Barlow said, should not be confused with company size or security spending. He described it instead as a strategic gap that can leave even well-funded organizations exposed, while some smaller businesses with limited budgets still achieve strong cybersecurity posture. The shortage of CISO-level leadership is forcing MSPs into a role many did not formally choose.
AI Is Moving Faster Than Governance
Barlow said MSPs and customers are, for the first time, moving at the same speed on AI adoption, creating a new challenge for partners responsible for securing customer environments. With end customers embedding agents and many organizations lacking AI security policies, the attack surface is expanding beyond traditional defenses, he said.
“That is very scary for you as an MSP trying to manage the technology within an organization,” he said. “Eighteen percent of organizations do not have an AI security policy, and 40 percent of enterprises today are embedding agents. That is crazy. And there is a $2.5 trillion in global AI spend, which is 10 times the amount that is being spent on cybersecurity.”
Partners Must Shift From Operators To Risk Advisers
Barlow said the partner opportunity is to help customers use AI safely while moving beyond basic technology operations. That means exposing policy gaps, running playbooks, protecting the new AI attack surface and changing the customer conversation around value as AI compresses the labor required for many services, he said.
“We have to change the conversation,” he said. “If we don’t, then we’re going to be out of business. Let me be clear. If we all don’t change and evolve with this, we will be out of business.”