Capability can be outsourced.
Accountability cannot.
Organisations often treat outsourcing as a sign of immaturity.
They assume mature organisations build capability internally.
Less mature organisations acquire it externally.
The reality is more complicated.
The misconception
Security capability is frequently discussed as though it belongs in one place.
It does not.
Most organisations rely on a combination of:
internal teams
service providers
specialist consultants
technology vendors
The question is not whether external support exists.
The question is how it is used.
Why the discussion often fails
Outsourcing is typically framed as a choice between:
control
capability
This creates a false distinction.
External expertise may improve capability.
It does not remove responsibility.
What actually matters
The important question is not:
“Who performs the work?”
It is:
“Who owns the outcome?”
The first question focuses on activity.
The second focuses on outcomes.
Why accountability changes the conversation
Once accountability is clear:
capability can be sourced flexibly
specialist expertise can be introduced
external support can expand or contract
Responsibility remains unchanged.
A useful reframing
Instead of asking:
“Should we outsource security?”
Ask:
“Which outcomes remain our responsibility regardless of who performs the work?”
Closing thought
Capability can be distributed.
“Accountability cannot.”