Capability can be outsourced.

Accountability cannot.

Organisations often treat outsourcing as a sign of immaturity.

They assume mature organisations build capability internally.

Less mature organisations acquire it externally.

The reality is more complicated.

The misconception

Security capability is frequently discussed as though it belongs in one place.

It does not.

Most organisations rely on a combination of:

  • internal teams

  • service providers

  • specialist consultants

  • technology vendors

The question is not whether external support exists.

The question is how it is used.

Why the discussion often fails

Outsourcing is typically framed as a choice between:

  • control

  • capability

This creates a false distinction.

External expertise may improve capability.

It does not remove responsibility.

What actually matters

The important question is not:

“Who performs the work?”

It is:

“Who owns the outcome?”

The first question focuses on activity.

The second focuses on outcomes.

Why accountability changes the conversation

Once accountability is clear:

  • capability can be sourced flexibly

  • specialist expertise can be introduced

  • external support can expand or contract

Responsibility remains unchanged.

A useful reframing

Instead of asking:

“Should we outsource security?”

Ask:

“Which outcomes remain our responsibility regardless of who performs the work?”

Closing thought

Capability can be distributed.

“Accountability cannot.”