Back to Blog

Who Owns Cyber Security When You Outsource IT Support?

By Jamie PopePublished 9 min readCyber Security
Diagram showing leadership, an IT support provider, employees and technology sharing cyber security responsibilities.

When you outsource IT support, you transfer a large amount of day-to-day cyber security work to a specialist provider. You do not transfer accountability. If a breach affects your customers, your data and your ability to trade, the business still owns the consequences, and leadership still has to explain the decisions that led there.

That distinction matters because most SME security gaps are not caused by a missing product. They are caused by a responsibility nobody claimed. This guide sets out who should own what when managed IT support is delivered by an external provider, and how to remove the gaps before an incident finds them for you.

Outsourcing cyber security work is not the same as outsourcing cyber risk

A provider can be contracted to patch devices, manage identities, configure Microsoft 365, monitor alerts and restore data. Those are operational duties and they can genuinely sit with a third party. Risk ownership is different. Risk ownership is deciding how much exposure the business will accept, funding the controls that reduce it and answering for the outcome when something goes wrong.

The UK Government and NCSC make the same point in the Cyber Governance Code of Practice, which places responsibility for cyber resilience with boards and directors rather than with suppliers. The NCSC Cyber Governance for Boards toolkit goes further and treats supplier relationships as something leadership must actively oversee.

So the useful question is not whether cyber security is outsourced. It is whether every individual responsibility has a named owner.

The four layers of cyber responsibility

In most SMEs, responsibility sits across four layers. Problems appear at the joins between them.

1. Leadership owns the business risk

Leadership decides what the organisation is protecting, what level of disruption it could survive and what it is prepared to invest. That includes setting risk appetite, approving budget, accepting or rejecting recommendations, and making sure someone in the business is accountable for cyber risk even when the work is delivered elsewhere.

Leadership also owns the consequences that no provider can absorb: regulatory duties, contractual commitments to customers, insurance conditions and the reputational impact of a serious incident. Where formal obligations apply, this overlaps with governance, risk and compliance work rather than with the service desk.

2. What Cyber Security Responsibilities Should Your IT Support Provider Have?

An outsourced IT support provider owns the operational work it has actually contracted to deliver. That scope varies enormously between providers, which is why it should be written down control by control rather than assumed.

Depending on the agreement, the responsibilities commonly held by an IT support provider include:

  • Patch and update management across servers, endpoints and key applications.
  • Endpoint protection deployment, policy management and alert handling.
  • Microsoft 365 configuration, including secure defaults, sharing controls and mailbox settings.
  • Identity and access management, covering multi-factor authentication, conditional access, privileged accounts, joiners and leavers.
  • Security monitoring and triage of alerts raised by the tooling in scope.
  • Vulnerability identification and remediation within agreed timescales.
  • Backup oversight, with recovery testing where that is explicitly included.
  • Security awareness training and phishing simulation where contracted.
  • Incident escalation and response, to the level of service purchased.

There is an important distinction hiding inside that list. Supplying a security product is not the same as configuring it. Configuring it is not the same as monitoring it. Monitoring it is not the same as responding to its alerts out of hours. And none of those is the same as taking responsibility for an outcome such as a tested recovery or a closed vulnerability.

Not every provider delivers every layer, and that is not automatically a failing. It becomes a failing when the customer believes a service is included that was never sold. NCSC guidance on supply chain and supplier security, which covers how to assess and contract with managed service providers, points at the same fix: make the boundary explicit in the contract. Where the requirement goes beyond standard support, managed cyber security is usually the right place to put it.

3. Employees own the process they have been taught

Staff cannot be held responsible for controls they cannot see. They can reasonably be expected to follow the processes they have been trained on: verifying unusual payment requests, reporting suspicious messages, not approving unexpected multi-factor prompts and not sharing credentials.

Attackers know this layer is the softest. Microsoft security research published on 2 September 2026 described attackers impersonating IT support staff through Microsoft Teams to talk users into granting access, which bypasses technical controls entirely by targeting a person following what looks like a normal process. The defence is a combination of training, clear reporting routes and an internal rule that genuine IT support will never ask for a code or a password.

4. Technology providers own the platform, not every configuration

Microsoft, and every other cloud vendor, operates a shared responsibility model. Microsoft shared responsibility guidance is clear that the vendor secures the platform while the customer remains responsible for data, identities, devices and access configuration.

In practice, this is where a great deal of SME risk quietly accumulates. A tenant can be fully licensed and still be exposed because conditional access was never tightened, legacy authentication was never disabled or external sharing was left open. Securing Microsoft 365 and cloud configuration is a customer-side duty, usually delegated to the IT provider, and almost never something the platform does for you.

Shared responsibility only works when it is written down

A responsibility matrix is the simplest tool available and one of the least used. For each control, record who operates it, who monitors it, who responds when it fails and who signs off the residual risk. Patching, MFA, backup testing, alert response, offboarding, licence management, firewall changes and incident communications should all appear.

Three things then need to be true. The matrix must match the contract, the contract must match what is actually happening, and the reporting must be good enough for leadership to tell. Monthly or quarterly reporting should show patch compliance, backup and restore evidence, security alerts handled, identity risks and open recommendations with owners against them.

Recovery deserves particular attention. Backup is a control and recovery is an outcome. If nobody has tested a restore, nobody owns recovery, no matter what the agreement says.

Incident response is the other area where gaps surface at the worst possible moment. Agree in advance who declares an incident, who contacts customers, who contacts insurers and regulators, who can authorise taking systems offline, and what happens at 2am on a Sunday. Under a co-managed arrangement, where an internal person or team shares the work with a provider, this needs to be even more explicit because both sides can reasonably assume the other is watching.

When Does Cyber Security Become an IT Consultancy Question?

Not every cyber security decision belongs in the service desk. Operational teams can patch devices, manage accounts, investigate alerts and maintain security controls. Decisions about risk appetite, technology investment, Microsoft 365 architecture, compliance requirements and resilience need a wider business view.

This is where strategic IT consultancy should connect operational IT with leadership priorities. Your provider sees the evidence every day: recurring incidents, ageing infrastructure, identity risks, unsupported applications, licensing problems and technical debt. That information should not stay buried inside tickets and dashboards. It should inform the technology roadmap, the cyber risk register, investment priorities, cloud strategy, continuity planning, compliance obligations, annual budgets and the decision about which risks to reduce, transfer or accept.

For an SME, this rarely justifies a full-time CIO. A vCIO or consultancy relationship can give leadership the context to turn technical evidence into business decisions. The objective is not only to make IT more secure. It is to make sure technology, cyber security, business risk and investment are pulling in the same direction.

Make ownership visible

Outsourcing IT support is a sound decision for most SMEs, and a good provider will carry the majority of the operational security workload. What it cannot do is take the accountability off the table. The organisations that handle this well are not the ones with the largest security budgets. They are the ones where every responsibility is visible, named and reviewed.

Much of this rests on whether preventive work is genuinely contracted in the first place, which is the theme of our guide to what proactive IT support actually means. It is also worth reading alongside whether managed IT support includes cyber security and what an MSSP does if you are deciding how much specialist capability you need.

The test is a single question. When a cyber risk sits between your people, your IT provider and your technology, who makes sure it does not fall through the gap?

Frequently asked questions

Is My IT Provider Responsible for Cyber Security?

An IT provider is responsible for the cyber security work it has contracted to deliver, such as patching, endpoint protection, identity management and Microsoft 365 configuration. Accountability for cyber risk remains with the business and its leadership.

Can a Business Outsource Cyber Security Completely?

No. A business can outsource the delivery and management of cyber security controls, but it cannot outsource accountability for risk, regulatory duties, contractual commitments or the consequences of an incident.

Who Is Responsible for Microsoft 365 Security?

Microsoft secures the underlying platform, while the customer remains responsible for data, identities, devices and access configuration. That customer-side responsibility is usually delegated to an IT support provider, but it should be written down.

What Cyber Security Responsibilities Should an IT Support Provider Have?

Typically patching, endpoint protection, Microsoft 365 configuration, identity and access management including MFA, security monitoring, vulnerability remediation, backup oversight, user awareness training and incident escalation, to the level of service purchased.

Who Is Responsible When an Employee Clicks a Phishing Link?

Responsibility is shared. The business owns training and internal process, employees are expected to follow the process they have been taught, and the IT provider is responsible for the technical controls, detection and response included in the agreement.

What Should a Cyber Security Responsibility Matrix Include?

For each control, record who operates it, who monitors it, who responds when it fails and who accepts the residual risk. Cover patching, MFA, backup testing, alert response, offboarding, licence management, firewall changes and incident communications.

Sources

Make every cyber responsibility clear

Cloud Agile can review your IT support agreement, Microsoft 365 environment, security controls and internal responsibilities, then show you exactly where ownership gaps exist and how to close them.

You get a clear improvement plan and no obligation to switch provider.

Book a Security Review