
Security
Outsourcing security: what stays yours anyway
A specialised supplier protects infrastructure better than you can internally: continuous monitoring, patching, current expertise. But access, training and processes stay yours, and that is where most incidents begin. A serious contract separates the two halves and requires periodic proof, not promises.
Almost no small or medium company can afford to do information security in-house. You need someone watching the systems at night, someone who knows what came out this week and has already seen a real attack. Relying on people who do it for a living is not surrender: it is the rational choice.
The trouble starts when "we take care of it" is heard as "it is no longer your problem". Because most breaches do not come through the door the supplier is watching.
The two halves, and where trouble actually happens
It is called the shared responsibility model and it applies to any managed service. Simplifying: the supplier answers for the machine, you answer for who gets in and what they do.
A serious supplier handles: system patching, separation between customers, encryption, event monitoring, backups, technical response when something goes wrong.
What stays yours, and cannot be delegated: who holds credentials and with what powers, what happens when someone leaves the company, which data you collect and why, who opens attachments, which third parties have access, and the decision on what to do when something happens.
It is an uncomfortable split, because the non-delegable half is also where most real incidents begin: a reused password, an access never revoked, a credible message asking for an urgent transfer. No supplier can patch that technically.
You can buy the monitoring. You cannot buy the discipline of the people holding the keys.The boundary that belongs in the contract
What to demand from a supplier
You don't need technical expertise to assess: you need precise requests and a willingness to put them in writing.
- Separation between customers. Ask how it is achieved. "They are on different servers" and "they are in the same application behind a filter" are two different worlds.
- Declared times, not promises. Within how long they notify you of an incident, how long to respond, how long to restore. With penalties, otherwise they are good intentions.
- Periodic restore drills. Not "we take backups": when was the last one restored, and what was verified. A backup never read back is a file you trust.
- An access log you can consult. You must be able to know who on their side touched your data, and when.
- The right to verify. Being able to ask for evidence — reports, audit outcomes, valid certifications — without negotiating it each time.
- An exit plan. How you get your data back, in what format and in what time, if one day you change your mind.
Certifications: what they say and what they don't
A certification such as ISO/IEC 27001 says the supplier has a documented security management system verified by an external body. It is a serious signal and worth asking for.
It does not say that you are safe. It says a method exists, that someone checked it, and that there is a declared scope — and that scope has to be read: a certification covering the head office but not the service they sell you is not much use.
Two concrete checks: ask for the certificate number and the body (verifiable in the public registers of accreditation bodies) and read the scope statement. Whoever is certified hands them over in a minute; whoever stalls has just answered you.
If you host other people's data, the chain gets longer
If your platform holds your customers' data, your supplier becomes a link in their chain. That means two things: you must be able to formally appoint them as processing data on your behalf, and their commitments must be at least equal to the ones you gave your own customers.
It is also why it pays to pick infrastructure where the technical controls are already in place: if the layer underneath is covered, what remains to govern are the organisational controls, which are yours.
Three things to do anyway, this week
- Second factor on everything that matters. Email, business system, bank, admin panels. It is the single measure that stops the most attacks, and it costs nothing.
- An up-to-date access list. Who holds the keys to what, including people who left and suppliers. It is almost always longer than anyone expects.
- One restore drill. Take yesterday's backup and try to bring it back. What you learn in that afternoon is worth more than any report.
The right question to ask a security supplier is not "are we protected?", to which they will say yes. It is: "what stays ours anyway, and how do you prove it to me?". Whoever has a ready answer to that usually has the rest in order too.