Home/Questions/Governance and workforce/In-house or outsourced security
Governance and workforce

Is the Applicant's network security managed in-house or outsourced?

Neither answer is better. What matters is whether the boundary between you and your provider has any gaps in it.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking who operates your security: your own staff, a managed provider, or a division of responsibilities between them. It usually leads to follow-up questions about the provider and the arrangement.

Why it is underwritten

Outsourced security concentrates capability and introduces a dependency and a boundary. Incidents frequently fall into the gap between what the provider assumed you were doing and what you assumed they were doing. Carriers ask because that gap is where response stalls.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is contractual and organisational, so it is attested. The most useful artefact is a written responsibility split.

PlatformWhere the setting livesWhat has to be true
ContractScope of services and a responsibility matrixA written split covering monitoring, patching, incident response, and backup. Attested
ContractCoverage hours and response service levelsWhat the provider commits to and when, which the monitoring question asks about directly
AuthorityWhat the provider may do without approvalContainment authority, since asking permission at three in the morning costs the hours that matter
Entra IDProvider access to your tenantHow the provider authenticates and what privilege they hold, which is measurable
GapsItems in neither party scopeA deliberate review of what neither side owns, which is where incidents fall
Write down who owns what

The most common failure in an outsourced arrangement is not poor service. It is a control that both parties believed the other was operating. A written responsibility matrix, reviewed once a year, prevents the discovery happening during an incident.

What a defensible yes requires

  • The split of responsibilities is written down and current.
  • The provider has defined coverage hours and response commitments.
  • Containment authority is agreed in advance.
  • Provider access to your environment is scoped and monitored.
  • Items owned by neither party have been actively looked for.

How this answer goes wrong

The arrangement is described as fully managed, and the provider monitors endpoints while patching, identity configuration, and cloud posture belong to nobody. Each party believed the scope was wider than the contract says.

Frequently asked

Is outsourcing viewed negatively?

No. For many organisations it delivers capability they could not staff. Carriers care about the boundary and the response commitment, not the model.

Should the provider be named?

Usually yes, and some carriers recognise particular providers. It also makes the coverage answer more concrete.

What about hybrid arrangements?

The most common model and the one most in need of a written split, because responsibility genuinely divides rather than transferring.

Does the provider need their own insurance?

It is worth requiring, and it belongs in the third-party contract question. A provider that causes your loss is a subrogation target.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture