Outsourcing Cybersecurity: What Stays Your Responsibility

Outsourcing cybersecurity means engaging a provider to manage agreed security functions, such as device protection, monitoring and incident response. Your business still decides its priorities, approves access and carries its own responsibilities. The agreement should make clear who does what, when they act, and what happens outside business hours.

Consider this example. A forty-person firm has 24/7 security monitoring and the tool works. At nine on a Saturday night a staff account starts downloading the client folder, and the alert fires exactly as it should.

What the contract never settled was who is permitted to disable that account before Monday, and whether they have to reach somebody at the firm first.

That is the gap that decides the outcome, and no amount of better tooling closes it. It closes when somebody writes down who may act, on what, and inside what window.

Firms that get caught here have often not been misled. They bought a product description and assumed a service.

Outsourcing cybersecurity suits a great many New Zealand businesses, usually because the skills are hard to hire and harder to cover for. It goes wrong in the gap between what a brochure implies and what an agreement obliges anyone to do.

So this covers three things: what outsourcing cybersecurity can and cannot move off your desk, how to read a proposal, and how to tell a year later that you got what you paid for.

What Does Outsourcing Cybersecurity Cover?

Scope is the thing to pin down, because packages differ. Outsourcing cybersecurity can cover device protection, monitoring, patching and incident response, and a narrower detection-only service is a legitimate offer rather than a deficient one. What no arrangement covers is the decisions about what matters, who should reach it, and what you tell people afterwards.

The confusion is understandable. Every proposal is written as a list of things the provider will do, and none of them is written as a list of things that remain yours.

Start any conversation about outsourced cyber security services by asking for that second list. A provider who can produce it without hesitating has thought about the arrangement properly. One who cannot has been selling you tooling and calling it a service.

The NCSC’s Critical Controls are a fair checklist to hold a proposal against. Multi-factor authentication, patching, application allowlisting, logging and alerting, least privilege and network segmentation each prevent, detect or contain attacks in different ways. A provider does not have to operate all of them to be offering a real service, but you do need to know which of them anybody is operating.

An outsourcing cybersecurity scope should name the systems and the security functions covered, the work the provider performs, and the work retained by your team or another supplier. Include devices, cloud services and user accounts where they are relevant. Check separately whether patching, backup management, containment and recovery are included, because those are the ones most often assumed. Ask which controls the provider operates, which they only advise on, and which stay with you, because the three lists are usually different and rarely written down.

Scope creep runs the other way too. A provider quoting outsourcing cybersecurity against a two year old picture of your network may not be covering the server bought since. Some providers run discovery and onboarding that pick new systems up, and others do not, so ask which yours does.

The fix is a written asset list that both sides agree to, reviewed on a schedule and updated whenever systems, staff arrangements or suppliers change. It is what keeps outsourcing cybersecurity describing the business you actually have.

The parts outsourcing cybersecurity never moves are these. Deciding what data matters, deciding who should have access, telling customers after a breach, and signing off the risk you accept are all yours whoever you hire.

Does Outsourcing Cybersecurity Transfer Your Privacy Responsibilities?

No. If a provider stores or processes personal information solely on your behalf, section 11 of the Privacy Act 2020 generally treats that information as held by your business rather than by the provider. Outsourcing cybersecurity does not change that, and you remain responsible for it. Where the provider also uses or discloses that information for its own purposes, both organisations can hold responsibilities under the Act, so what the provider actually does with the information matters and not just the label on the contract.

Outsourcing cybersecurity diagram showing four tasks moving to a provider while accountability stays with the business

Section 11 can apply to an agent overseas, which is why an overseas security operations centre does not by itself move your responsibility. That does not make every offshore arrangement legally identical. Whether the recipient is acting solely on your behalf is the question, and a disclosure overseas can bring Principle 12 into play, so ask how your provider is structured rather than assuming either answer.

The notification duty sits with you. Where there are reasonable grounds to believe a privacy breach has caused, or is likely to cause, serious harm, you must notify the Privacy Commissioner and the affected people as soon as practicable, and exceptions can apply to telling the people themselves. Not every security incident meets that test. Agree in advance who investigates, who supplies the information needed to assess the harm, and who coordinates any notification.

Contracts can and should allocate cost and responsibilities between you and the provider. What a contract cannot do is remove a statutory obligation the Act places on you, because statute created it rather than your agreement with a supplier. Your provider can carry out agreed tasks within it.

Keep that in mind when an outsourcing cybersecurity proposal offers to take security off your hands. It can take the work. It cannot take the answer you will have to give.

None of this makes outsourcing cybersecurity a bad idea. It makes the arrangement a partnership with an unequal share of the consequences, and you want to know that before you sign, not during a bad week.

It also shapes what you should ask for in outsourcing cybersecurity reporting. If the answer after an incident has to come from you, the monthly report needs to contain the material that answer will be built from.

The practical consequence is a small one and people skip it. Know what personal information you hold and where, because you will be asked at speed and your provider cannot answer it for you.

What Is the Difference Between an MSP and an MSSP?

An MSP runs your IT and an MSSP manages security functions. Many New Zealand businesses buy both from one company, which is why cyber security outsourcing here often does not mean hiring a separate specialist firm. The distinction still matters when you are buying outsourcing cybersecurity, because the two disciplines fail in different ways and are staffed differently.

A managed IT provider is measured on uptime and on tickets closed. Security work is harder to see, because most of it is preventive and produces no visible event. An absence of incidents does not by itself establish that the work is being done, which is why the reporting matters more here than it does for a helpdesk.

That asymmetry is why outsourcing cybersecurity is easy to buy badly. A slow helpdesk generates complaints within a week. A weak security service can generate nothing at all until the year it does.

The risk in buying both from one supplier has nothing to do with competence. It is that security work rarely arrives with a caller waiting, so it can slip behind the support queue unless somebody has been made accountable for it.

Two questions are worth asking. Who does the security work and are they the same people answering the helpdesk, and what security experience and qualifications do they hold. Qualifications alone do not settle whether a provider is any good, but the answers tell you how outsourcing cybersecurity is actually staffed at their end.

Ask about the after-hours arrangement third. Continuous cover is often staffed through a dedicated security operations centre rather than the helpdesk roster. Ask how yours is arranged, whether a person reviews alerts at those hours or only the tooling runs, and what that team is permitted to do without waking you.

Co-managed IT is the middle option and it suits businesses that already have somebody technical. The provider takes the specialist work and the internal person keeps the context.

What Should You Ask an Outsourced Cyber Security Provider?

Ask about scope and budget together, because two quotes for outsourced cyber security can describe genuinely different services without either provider being dishonest. Comparing the monthly figure before you have matched the scopes tells you very little.

Several things drive the difference. How many users and devices are covered, which environments are in scope, the hours of service, what onboarding involves, and whether specialist response and recovery are included. The billing model is one more variable, because per user, per device and per site produce different totals for the same business, none of them wrong, so work out what your own environment costs under each before you compare anybody.

Put both outsourcing cybersecurity proposals against the same list before you look at the numbers. Which controls they operate and which they only advise on. What hours a human is available. What response commitment goes in writing, whether testing is included, and what happens in an incident that runs past a day.

The word monitoring does a great deal of concealed work. It can mean a person watching a console, or a tool generating alerts no one is contracted to read inside any particular window.

The same caution applies to the word managed. It appears in most proposals for outsourcing cybersecurity and carries no fixed meaning, so ask what is managed, by whom, and to what standard.

Ask what is excluded. Incident response beyond a set number of hours, forensic investigation, legal notification support and out-of-hours work are all commonly outside a monthly fee, and which of them applies varies by agreement, so get the list for the one in front of you.

Cyber security outsourcing is one of those purchases where doing that arithmetic first can change which quote wins.

Then ask what it costs to leave an outsourcing cybersecurity arrangement. Who holds the tenancy, who holds the licences, and what you get on the way out are questions that are cheap to ask now and expensive to discover later.

Get both proposals to answer the same twelve or so questions in writing before anybody presents. It turns a sales meeting into a comparison. Of everything here, it is the step that most often changes which provider a business ends up with.

Detection and response deserves its own question in any outsourcing cybersecurity proposal, because that is where the money goes and where definitions vary most. Our post on managed detection and response sets out what the term covers.

How Do You Tell a Real Security Service From a Helpdesk?

Ask what the last month produced, proportionate to what you actually bought. Outsourcing cybersecurity that is actually running produces records as a by-product of the work. One that is not tends to produce invoices and a reassuring quarterly conversation.

Diagram showing reporting following the agreed outsourcing cybersecurity scope, with work outside that scope producing no report

Useful things to ask for include a patch compliance figure, a list of accounts holding administrative rights, the alerts raised and what was done about each, and the date of the last restore test. Which of them is reasonable to expect depends on what the agreement covers, so match the request to the scope rather than to a fixed list.

A provider already reporting on those will have them to hand. One that has to assemble them from scratch is telling you the reporting was not built into the service, which is worth knowing without being proof of anything else.

Push on the alert list in particular. Alerts raised, alerts investigated and alerts closed as nothing are three different numbers, and a service reporting only the first is describing its tooling.

A month with nothing in it is not evidence of anything on its own. Ask what was tested in that month, because an uneventful one is when the work of outsourcing cybersecurity should still be visible.

Timing changes the answer you get. Agreeing the reporting at the start builds it into the service. Asking in month fourteen turns it into a favour.

Read the first report properly and ask about anything you do not understand. The habit of reading it is what keeps outsourcing cybersecurity honest, and it needs somebody named on your side of the agreement whose job that is.

An independent security audit is the other way to check, and renewal is the time for it.

What Should a Cyber Security Outsourcing Contract Cover?

An outsourcing cybersecurity contract has five areas to settle: what is covered and what is excluded, monitoring and response, authority and escalation, provider access, and costs and exit. Few agreements deal with all five, and the ones that do were usually written by somebody who had been through an incident.

Contract area What to establish
Coverage and exclusions Which systems, accounts and security functions are included, who handles the gaps, and how scope changes when the environment does.
Monitoring and response When tools collect alerts, when people review them, and what starts the response clock. Distinguish acknowledgement, investigation, containment and recovery.
Authority and escalation Which actions are pre-authorised, what needs business approval, who the fallback contact is, and how critical systems are handled.
Provider access How privileged access is restricted and protected, which subcontractors can reach systems or data, and how supplier incidents are communicated.
Costs and exit What is included, optional or separately charged, who controls the tenancy and accounts, and how data, access and subscriptions are handled at the end.

Read the response commitment before anything else, and check which action it measures. A four hour response can mean acknowledgement, investigation, containment or recovery, and those are four different promises. It also means one thing at 2pm on a Wednesday and something else at 9pm on a Saturday. Whichever hours apply, they belong on the page in writing.

Authority gets forgotten entirely. If your provider sees an account being used from overseas outside working hours, that is a signal to investigate rather than proof of a compromise, so what happens next has to be agreed in advance. Which containment actions are pre-authorised, which need somebody at your end to approve them, and who the fallback contact is. Requiring approval is reasonable where the action would disrupt a critical system, provided somebody can actually be reached.

Then there are the exit terms, which nobody negotiates and most businesses eventually need. Whether the Microsoft tenancy sits in your name or is held for you under a provider agreement decides how hard leaving is, and either can be made to work. What matters is that the transfer terms are written down before you need them rather than negotiated on the way out.

Get the answer in writing before you need it, including who is called when the first contact cannot be reached.

Provider access is the outsourcing cybersecurity area most often skipped. The joint advisory for managed service providers and their customers is explicit about restricting and protecting the access a provider holds and about agreeing incident arrangements in advance. Ask how privileged access is controlled, which subcontractors can reach your systems or data, and how you would be told about an incident at the provider rather than at your end.

None of these areas is unusual or adversarial. A provider running a serious outsourcing cybersecurity practice will have answers ready, because their better clients have asked before.

When Is Outsourcing Cybersecurity the Wrong Answer?

When nobody inside the business owns the relationship. An information security outsourcing arrangement with no internal owner drifts. The provider does what the contract says, and nobody is asking whether the contract still describes the business.

It is also the wrong answer while the real difficulty is decision-making. A firm that cannot decide who should have access to the finance system will not be helped by paying somebody else to monitor it. That is a condition to resolve rather than a permanent bar, and naming an internal decision owner is usually what resolves it.

Timing matters too. A business part-way through a system migration is not barred from outsourcing cybersecurity, but the scope will be describing a network that is about to change, so plan the change into the agreement and agree up front how scope moves when the environment does.

Very small businesses are a different case, though not the case people assume. It turns on what you hold and what you depend on rather than on how many people you employ. A six-person practice holding client health records has an obvious exposure, and a six-person trade business holding almost no personal information still faces payment fraud, account compromise and the loss of the systems it quotes and invoices from. Scope the arrangement to that rather than to headcount. Where the basics are the gap, cyber readiness covers what those are.

Try describing what your outsourcing cybersecurity provider does for you in three sentences. If you cannot, you are paying a subscription.

Watch for the arrangement that exists to satisfy somebody else. Outsourcing cybersecurity bought to answer a client questionnaire or an insurer, without anybody internally reading the reports, produces a certificate and not much protection.

None of that argues against outsourcing. It argues for buying it deliberately, with somebody named on your side of the agreement.

Who Answers When It Happens?

The whole arrangement turns on that question, and it is answerable in advance. Every test in this post is one we expect to be asked, so here are our answers to the ones that decide it.

Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand.

Our cyber security team operates controls as well as advising on them, and which of those applies to you is set by the service you agree rather than assumed. Where continuous monitoring is part of that service we say what runs automatically and what a person reviews, and we agree in writing what we may act on without ringing you first, because two in the morning is not the moment to be looking for permission.

We report on what was raised and what was done at the cadence the agreement sets. We also tell clients which parts stay theirs, because those parts do not move and pretending otherwise helps nobody.

Ask us the same questions you would ask anybody else. Outsourcing cybersecurity is worth what the agreed scope and the reporting behind it can show.

You can also connect with us on LinkedIn for more on this topic.

Frequently Asked Questions

What are the benefits of outsourcing cybersecurity?

Coverage you cannot staff, tooling you would not buy outright, and somebody accountable for watching at hours you do not work. Those are real and every provider will list them. The benefit worth checking is narrower: whether the arrangement produces evidence, proportionate to what you bought, that the agreed work is happening.

Is outsourcing cybersecurity the same as managed IT?

They overlap. Managed IT covers the operation and support of business technology, while outsourced cybersecurity focuses on agreed security functions. One provider can deliver both. Check who owns the security work, what is included and how alerts are handled, rather than relying on the service label.

Who is accountable if your provider loses your data?

Your business retains privacy responsibilities for personal information a provider processes solely on its behalf, which is what section 11 of the Privacy Act 2020 does. A provider that also uses the information for its own purposes can have duties of its own. Agree an incident process in advance, because responsibility follows the actual roles rather than the wording of the contract.

What is an MSSP?

An MSSP is a managed security service provider. It manages security functions for other organisations, which may include device protection, monitoring and response. Services vary, and the label alone does not establish round-the-clock human coverage or incident recovery.

Should security and IT support come from the same company?

It is a common and workable arrangement, and one provider can do both well. The condition is that somebody owns the security work, because it produces fewer visible events than support does and can slip behind the ticket queue. Ask what the security work covered in the last reporting period and who is accountable for it.

Why do two security quotes differ so much?

Because they are pricing different scopes, and often on different models. Per user, per device and per site produce very different totals for the same business. Work out what your own environment costs under each before comparing anybody, and check what sits outside the monthly fee, because incident response past a set number of hours is commonly excluded.

What should a cybersecurity contract include?

Five areas. What is covered and what is excluded, monitoring and response with the hours stated and the measured action named, authority and escalation covering what the provider may do without reaching you, provider access including subcontractors, and costs and exit naming who holds the tenancy and licences. Few agreements deal with all five, and authority to act is the one left out first.

How do you know your provider is actually doing the work?

Ask what the last reporting period produced, proportionate to the service you agreed. Patch compliance, who holds administrative rights, which alerts were raised and how each was resolved, and when a restore was last proved are all useful to see where the agreement covers them. A provider already reporting on those will have them to hand.

Is outsourcing cybersecurity cheaper than hiring?

It can be, but headcount alone does not settle the comparison. Compare the skills, hours and functions each option provides, including leave cover and specialist support. Include onboarding, incident charges and the time your business still has to spend managing the arrangement.

Does a small business need outsourced cybersecurity?

It depends on what you hold and what you depend on, not on headcount. Get the basics in place first either way: multi-factor authentication everywhere, patching, and a backup copy that cannot be deleted. A small firm holding client records or payment data has an obvious exposure, and one holding neither still faces payment fraud, account compromise and the loss of the systems it runs on.

What does 24/7 monitoring actually mean?

It should mean the monitoring runs continuously, but it does not by itself guarantee that a person investigates or acts at any hour. Ask separately about human review, response commitments and which action they measure, containment authority and recovery support. Have the agreed coverage written into the service scope.

Who is liable if an outsourced provider causes a breach?

Outsourcing does not automatically remove your obligations or excuse the provider. Privacy responsibilities depend on the arrangement and on what the provider does with the information. What you can recover commercially is a separate question governed by the contract and the insurance behind it, so avoid assuming either that the provider takes all liability or that it has none.

Does Exodesk provide outsourced cybersecurity in New Zealand?

Yes. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. We agree the scope, report on what was raised and what was done at the cadence the agreement sets, and put in writing what we may act on without calling first.

NEXT STEP

Know who acts before an alert arrives

Looking to outsource cybersecurity? Talk to Exodesk about the systems you need covered, the work your team will retain, and the monitoring and response arrangements your business needs. Agree the scope, the escalation contacts and the authority to act before the service starts.

Not sure where to start? Request an IT assessment.

Start typing and press Enter to search

Ransomware protection banner showing an open padlock and a row of screens going darkPhishing scams banner showing two identical envelopes with only one outlined as the fake Call Us Now