Is the Applicant's network security managed in-house or outsourced?
Neither answer is better. What matters is whether the boundary between you and your provider has any gaps in it.
What the carrier is actually asking
The carrier is asking who operates your security: your own staff, a managed provider, or a division of responsibilities between them. It usually leads to follow-up questions about the provider and the arrangement.
Why it is underwritten
Outsourced security concentrates capability and introduces a dependency and a boundary. Incidents frequently fall into the gap between what the provider assumed you were doing and what you assumed they were doing. Carriers ask because that gap is where response stalls.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is contractual and organisational, so it is attested. The most useful artefact is a written responsibility split.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Contract | Scope of services and a responsibility matrix | A written split covering monitoring, patching, incident response, and backup. Attested |
| Contract | Coverage hours and response service levels | What the provider commits to and when, which the monitoring question asks about directly |
| Authority | What the provider may do without approval | Containment authority, since asking permission at three in the morning costs the hours that matter |
| Entra ID | Provider access to your tenant | How the provider authenticates and what privilege they hold, which is measurable |
| Gaps | Items in neither party scope | A deliberate review of what neither side owns, which is where incidents fall |
The most common failure in an outsourced arrangement is not poor service. It is a control that both parties believed the other was operating. A written responsibility matrix, reviewed once a year, prevents the discovery happening during an incident.
What a defensible yes requires
- The split of responsibilities is written down and current.
- The provider has defined coverage hours and response commitments.
- Containment authority is agreed in advance.
- Provider access to your environment is scoped and monitored.
- Items owned by neither party have been actively looked for.
How this answer goes wrong
The arrangement is described as fully managed, and the provider monitors endpoints while patching, identity configuration, and cloud posture belong to nobody. Each party believed the scope was wider than the contract says.
Frequently asked
Is outsourcing viewed negatively?
No. For many organisations it delivers capability they could not staff. Carriers care about the boundary and the response commitment, not the model.
Should the provider be named?
Usually yes, and some carriers recognise particular providers. It also makes the coverage answer more concrete.
What about hybrid arrangements?
The most common model and the one most in need of a written split, because responsibility genuinely divides rather than transferring.
Does the provider need their own insurance?
It is worth requiring, and it belongs in the third-party contract question. A provider that causes your loss is a subrogation target.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture