Integrated Solutions
Key Considerations for Outsourcing Security
In conversation with Security, Alan Saquella provides three pros and cons to outsourcing security.

It’s no doubt that security should be an essential part of daily operations. The question comes when trying to decide the best solution for your needs. Should you hire your own team, or form a contract with a security provider?
There is no universal answer to that question. Your available resources and individual risk factors will heavily determine which solution works best for your organization.
In conversation with Security, Alan Saquella provides three pros and cons to outsourcing security.
What are the benefits of outsourcing security?
-
Access to specialized expertise
Outsourcing can provide access to security professionals, technologies, and capabilities that an organization may not have internally. This is particularly valuable for cybersecurity, where threats and technologies change rapidly, but it can also apply to physical security, investigations, executive protection, monitoring, and emergency response.
-
Cost and resource efficiency
Organizations can reduce the expense of recruiting, training, retaining, and equipping a large internal security staff. A security provider may also spread technology and personnel costs across multiple clients, potentially providing capabilities at a lower overall cost.
-
Scalability and 24/7 capabilities
Security needs can change quickly. Outsourcing can allow an organization to scale personnel or technical capabilities up or down as threats change. Managed security services, security operations centers, monitoring, and physical security operations can also provide around-the-clock coverage that may be difficult for a smaller internal team to maintain.
The question shouldn't be, "Should we outsource security?" It should be, "Which security functions should we outsource, which should remain internal, and how do we maintain accountability for both?"
What are the drawbacks to outsourcing security?
-
Loss of direct control and organizational knowledge
An outside provider may not understand the organization's culture, operations, assets, or risk tolerance as deeply as an internal security team. This can be especially problematic when security decisions require intimate knowledge of the business.
-
Third-party risk
Outsourcing doesn't eliminate risk; it can transfer and sometimes introduce risk. A security vendor may have access to sensitive information, systems, facilities, employees, or security procedures. A weakness in the vendor's cybersecurity, personnel screening, or operational practices can become the organization's problem.
-
Conflicting priorities and accountability
A contractor's primary objective may be fulfilling a contract rather than protecting the organization's long-term interests. If the relationship is poorly managed, organizations can encounter issues involving service quality, employee turnover, communication, response times, or accountability when something goes wrong.
“The question shouldn't be, ‘Should we outsource security?’ It should be, ‘Which security functions should we outsource, which should remain internal, and how do we maintain accountability for both?’" says Saquella. “The biggest mistake is assuming that outsourcing responsibility means outsourcing accountability. The organization ultimately remains responsible for protecting its people, assets, information, and reputation.”
“Your available resources and individual risk factors will heavily determine which solution works best for your organization.”
Asking yourself these questions can help leaders not only make a decision about the source of their security but can also help you understand your organization better as a whole. That way you can strengthen future decision making the next time a security concern makes itself known.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








