Back
Outsourcing security: what stays yours anyway

Security

Outsourcing security: what stays yours anyway

A specialised supplier protects infrastructure better than you can internally: continuous monitoring, patching, current expertise. But access, training and processes stay yours, and that is where most incidents begin. A serious contract separates the two halves and requires periodic proof, not promises.

12 Aug 2026 · 9 min read · updated on 27 Aug 2026

Almost no small or medium company can afford to do information security in-house. You need someone watching the systems at night, someone who knows what came out this week and has already seen a real attack. Relying on people who do it for a living is not surrender: it is the rational choice.

The trouble starts when "we take care of it" is heard as "it is no longer your problem". Because most breaches do not come through the door the supplier is watching.

The two halves, and where trouble actually happens

It is called the shared responsibility model and it applies to any managed service. Simplifying: the supplier answers for the machine, you answer for who gets in and what they do.

A serious supplier handles: system patching, separation between customers, encryption, event monitoring, backups, technical response when something goes wrong.

What stays yours, and cannot be delegated: who holds credentials and with what powers, what happens when someone leaves the company, which data you collect and why, who opens attachments, which third parties have access, and the decision on what to do when something happens.

It is an uncomfortable split, because the non-delegable half is also where most real incidents begin: a reused password, an access never revoked, a credible message asking for an urgent transfer. No supplier can patch that technically.

You can buy the monitoring. You cannot buy the discipline of the people holding the keys.The boundary that belongs in the contract

What to demand from a supplier

You don't need technical expertise to assess: you need precise requests and a willingness to put them in writing.

Certifications: what they say and what they don't

A certification such as ISO/IEC 27001 says the supplier has a documented security management system verified by an external body. It is a serious signal and worth asking for.

It does not say that you are safe. It says a method exists, that someone checked it, and that there is a declared scope — and that scope has to be read: a certification covering the head office but not the service they sell you is not much use.

Two concrete checks: ask for the certificate number and the body (verifiable in the public registers of accreditation bodies) and read the scope statement. Whoever is certified hands them over in a minute; whoever stalls has just answered you.

If you host other people's data, the chain gets longer

If your platform holds your customers' data, your supplier becomes a link in their chain. That means two things: you must be able to formally appoint them as processing data on your behalf, and their commitments must be at least equal to the ones you gave your own customers.

It is also why it pays to pick infrastructure where the technical controls are already in place: if the layer underneath is covered, what remains to govern are the organisational controls, which are yours.

Three things to do anyway, this week

  1. Second factor on everything that matters. Email, business system, bank, admin panels. It is the single measure that stops the most attacks, and it costs nothing.
  2. An up-to-date access list. Who holds the keys to what, including people who left and suppliers. It is almost always longer than anyone expects.
  3. One restore drill. Take yesterday's backup and try to bring it back. What you learn in that afternoon is worth more than any report.

The right question to ask a security supplier is not "are we protected?", to which they will say yes. It is: "what stays ours anyway, and how do you prove it to me?". Whoever has a ready answer to that usually has the rest in order too.

What does managed security cost for a small company?
Less than one incident — but that is a convenient answer. In practice the cost depends on how many machines are watched and with what response time: a service with round-the-clock cover and penalties costs a multiple of one answering within business hours. Choose based on what a day of downtime costs you.
Isn't our trusted IT person enough?
To keep things running, often yes. For security the issue is continuity: one person cannot watch systems at night, in August and while at the dentist. The model that works is your IT person, who knows the company, plus a service covering the hours they are not there.
What do we ask for after an incident?
A written report with: what happened, when it was detected, what was touched, what was done to contain it and what changes so it doesn't repeat. If it doesn't arrive spontaneously within a few days, that is a signal about the supplier.
Do we need cyber insurance?
It can make sense, but read the exclusions: nearly every policy requires minimum measures — second factor, backups, patching — and does not pay if they were missing. In practice it forces you to do the things that needed doing anyway.
Ready to publishShare on LinkedIn