For more than 25 years, I have had the privilege of helping a privately held, multi-site manufacturing company evolve from a small business with a single-server environment into an organization with approximately $100 million in annual revenue, seven locations, about 150 computer users and roughly 250 endpoints.
Every organization’s journey is different, but the maturity challenges this company faced are common among growing SMBs. Technology that begins as a support function eventually becomes operationally essential. Responsibility becomes distributed. Risk grows faster than informal management practices. At some point, keeping systems running is no longer enough.
Phase 1: Building the foundation
My relationship with the company began while I was operating my managed-services business. At that stage, IT was relatively simple: a small network, a single Windows server and limited technology supporting a much smaller organization.
As the business expanded, its systems had to expand with it. Over the following years, I designed, implemented and supported the infrastructure required for a growing manufacturing operation: networks, servers, virtualization, remote connectivity, endpoint management, Microsoft technologies, security appliances and day-to-day support.
The important result was not the technology itself. The systems enabled the company to add locations, users, processes and operational capacity without allowing its IT foundation to become the limiting factor.
Phase 2: From MSP provider to embedded IT leadership
After operating the managed-services practice for approximately ten years, I shifted toward supporting a smaller number of clients as their extended IT staff. With this manufacturer, my role became closer to that of an IT consultant and manager.
I was no longer focused only on implementing or repairing technology. I was helping leadership make decisions about architecture, priorities, business continuity, vendors and long-term operational needs.
By then, however, the organization had become too dependent on one person’s knowledge. Reducing that dependency was better for the business, even though it meant transferring responsibilities I had handled for years.
I supported the decision to bring in a professional MSP, helped onboard the provider and transferred the company-specific technical and operational knowledge the MSP needed to assume day-to-day responsibility.
The MSP transition worked—but revealed another gap
Initially, I continued filling a technical gap because I understood the company’s unique systems, configurations, products and operating processes in ways a new provider could not immediately replicate. Over time, that knowledge was successfully transferred.
The MSP was doing what it had been engaged to do: operating infrastructure, supporting users, responding to technical issues and maintaining systems.
But a different need was becoming visible. No one had clear responsibility for cybersecurity governance, executive risk decisions, policy development, security-program direction or ensuring that identified requirements were converted into accountable operational work.
This was not evidence that the MSP had failed. It was evidence that operational IT support and CISO leadership are different functions. The organization needed both—and needed a close working loop between them.
Phase 3: Deliberately evolving into a vCISO role
Rather than duplicate services the MSP already provided, I deliberately changed my role. I moved from IT management toward governance, risk and executive cybersecurity leadership, eventually formalizing that work as a fractional CISO practitioner.
Working with company leadership, the MSP and a professional vCISO partner network, I helped establish the organization’s first formal information security program. The program is aligned with CIS Controls v8.1 and is intended to create repeatable governance rather than a collection of disconnected security activities.
The work has included:
- A formal CIS Controls v8.1-aligned governance, risk and compliance program
- Cybersecurity policies, standards and supporting procedures
- Incident-response policy and procedures
- Disaster-recovery policy and procedures
- An AI acceptable-use policy, governance model and safeguards initiative
- OT network segmentation and multi-factor authentication improvements
- Executive communication, risk prioritization and remediation oversight
When cyberinsurance exposed a governance gap
One of the clearest examples came from reviewing cyberinsurance requirements. That review exposed an access-control gap involving remote access to operational technology systems.
The issue could not be solved by a policy statement alone. It required management attention, technical design and close cooperation with the MSP and operational stakeholders. The resulting project introduced stronger segmentation, secure remote-access controls and multi-factor authentication.
The lesson was larger than the control itself: requirements can exist on paper while the operational environment tells a different story. Someone must compare the two, identify the business exposure and drive the work through to implementation.
What this experience taught me
A capable MSP is an essential operating partner, but no provider automatically owns every governance or business-risk responsibility. The client retains risk. The MSP delivers and supports technology. The vCISO helps leadership decide what matters, establishes the program and closes the loop between requirements and operations.
MSPs operate technology. vCISOs govern risk. Organizations need both.
The strongest security outcomes come from closing the loop between MSP operations and CISO oversight.
That is the philosophy behind ChannelCISO. My role is not to replace an MSP. It is to work with the MSP and the client so security risks, requirements and decisions become practical, assigned and completed work.
Why this matters for other MSPs and SMBs
Many growing organizations are somewhere along the same maturity path. They may have excellent technical support but fragmented governance. They may have policies without ownership, findings without remediation, or cyberinsurance and compliance demands that no one is coordinating.
My experience gives me a perspective that is both operational and strategic. I understand how technology is implemented, how MSP delivery works, where executive decisions are required and why governance must remain connected to the teams doing the actual work.