"You Can’t Outsource the Risk, But You Can Outsource the Blame" – A Hard Truth for Organisations

"You Can’t Outsource the Risk, But You Can Outsource the Blame" – A Hard Truth for Organisations

As organisations grow, so does their reliance on third-party vendors for critical services - IT, security, cloud operations, and more. Outsourcing has become the norm. But here’s the hard truth: while you can outsource the work, you can’t outsource the risk.

Let’s be clear: accountability stays with you.

The Illusion of Outsourced Security

Many organisations believe outsourcing cybersecurity functions or data management will reduce their exposure to risks. In reality, it often shifts the focus away from internal responsibilities, leading to vulnerabilities. When a breach happens, the blame game starts, but guess who ultimately pays the price? The organisation—not the vendor.

Therefore, when you hand over your data, your IT infrastructure, or your customer service to an external vendor, you are not transferring the inherent risks that come with them. You are simply sharing the responsibility.

Third-Party Risk is Still YOUR Risk

Here’s the catch—when a vendor fails to protect your data, it's still your brand, reputation, and bottom line on the line. And while you may be able to shift the legal or financial consequences through contracts, the impact on trust and business continuity remains firmly in your court. The consequences land squarely on YOUR shoulders.

What Should You Do?

  1. Set Clear Expectations: Make sure that all third-party providers understand your security policies and integrate them into their operations.
  2. Crystal Clear Contracts: Ensure your contracts specify who is accountable for what. Outline security requirements, incident response protocols, and potential liabilities.
  3. Continuous Monitoring: Don’t just trust their certifications and compliance reports—conduct regular audits and insist on transparency. Think of it as your ongoing relationship check-up.
  4. Shared Responsibility Model: Security is a partnership. Even in the cloud, understanding the shared responsibility model is critical - where the provider’s duties end, and yours begin.
  5. Have a Strong Incident Response Plan: Plan for the worst. If something goes wrong, be ready to act swiftly. A coordinated response can make all the difference in managing the fallout.

Blame Won’t Protect You

At the end of the day, outsourcing blame doesn’t safeguard your organisation. Proactive risk management does. By owning the risks, even when partnering with third parties, you can strengthen your security posture and protect your business from unnecessary exposure.

Have you experienced challenges with third-party risk? How do you ensure vendors uphold your security standards?

Cameron Lynch

Head of Cyber Security & Governance at BGC | Business Leader | Strategy & Risk | Secure by Design

1 个月

It’s similar to how misinformation spreads in the media. When a data breach involving client data is announced, the public often remembers only the company’s name and rarely considers the third party involved in follow-up blame articles. This highlights the importance of accountability. Organisations must realise that, regardless of outsourcing, the responsibility for protecting client data ultimately falls on them. When incidents occur, it’s the company’s reputation that’s on the line, not just that of the service provider.

Patrick Taiwo PMP?, PMI-ACP?, PSM?, DASSM, DAVSC, DAC, SSM

IT Consultant at Patoman Technology Solutions LLC

1 个月

Very much on point sir, stay fully involved and own it.

回复
Segun FATOKI

Experienced Information Technology Professional | Enterprise Agility | Digital Transformation | Driving Innovation in Project & Product Management| Passionate about Cybersecurity| Value Co-creation & Continuous Learning

1 个月

Good one sir… in scrum, as a product owner, you can nominate someone from the team to be responsible for your accountability but you are still ACCOUNTABLE.

Russell Andrews

Founder and Director at Flowspring Consulting. Director of Agile Practice at the Ministry of Social Development. SAFe certified Premier Trainer. SAFe SPCT.

1 个月

Love this

要查看或添加评论,请登录

Pete Omotosho的更多文章

  • Learning the Hard Way: The Cost of Experiential Learning in Business and Life

    Learning the Hard Way: The Cost of Experiential Learning in Business and Life

    There is a famous quote often attributed to Will Rogers: “There are three kinds of men. The one that learns by reading.

    1 条评论
  • Enhancing Cybersecurity for Mobile Applications: Protecting What Matters Most!

    Enhancing Cybersecurity for Mobile Applications: Protecting What Matters Most!

    In a world where our lives revolve around mobile apps, it's crucial to remember the profound impact they have on our…

    2 条评论
  • Business Agility: A Necessity in 2022

    Business Agility: A Necessity in 2022

    The new year is here. The new year offers an opportunity to rest both at the enterprise level and the individual level.

    2 条评论
  • Swiss Army Knife and Disciplined Agile

    Swiss Army Knife and Disciplined Agile

    The Disciplined Agile toolkit can be likened to the Swiss Army Knife. Just like the way it is imperative for those who…

    3 条评论
  • Managing Knowledge Workers’ Work

    Managing Knowledge Workers’ Work

    An average enterprise plays a major emphasis on the utilisation of people on their projects and initiatives. The focus…

  • Freedom with Disciplined Agile

    Freedom with Disciplined Agile

    Disciplined Agile (DA) is an agnostic, hybrid tool kit that binds many proven Agile, Lean, and conventional approaches…

  • When the team manager becomes the Product Owner

    When the team manager becomes the Product Owner

    Who is the Product Owner? The Product Owner (PO) is an important role within the Scrum Team. Great POs have amazing…

    1 条评论
  • The Agile Way

    The Agile Way

    Welcome to the New Year, 2019. We now live in a dynamic world.

  • Agile Adoption Precedes Agile Transformation

    Agile Adoption Precedes Agile Transformation

    Agile transformation seems to be everywhere. Almost every organisation, around the world, now proclaim to be going…

  • What does being good mean?

    What does being good mean?

    “Striving to be good is the ultimate struggle of every man. Being bad is easy, but being good requires sincere…

    2 条评论

社区洞察

其他会员也浏览了