Outsourcing IT support transfers tasks. It does not transfer the business’s accountability for customer data, employee access, financial systems or operational continuity. A provider may manage laptops, Microsoft 365, firewalls and backups, but leadership still needs to know which controls exist, who operates them and what evidence proves they are working.
The dangerous position is not outsourcing. It is assuming that “security is included” without defining the responsibilities.
Create a shared-responsibility matrix
For every important control, record:
- who approves the policy;
- who configures the control;
- who monitors it;
- who responds to an exception;
- who reports to management;
- which action requires customer authority;
- which specialist service is outside normal support.
| Control | Customer responsibility | Provider responsibility |
|---|---|---|
| User access | Approve roles, joiners, movers and leavers. | Create, change and remove access with evidence. |
| MFA | Approve policy and exceptions. | Configure, support registration and report gaps. |
| Endpoints | Use approved devices and report loss. | Manage protection, patching and compliance. |
| Backup | Approve scope, retention and recovery priorities. | Operate, monitor, test and report as contracted. |
| Incident response | Provide business decisions and communication authority. | Triage, contain within authority and escalate. |
The matrix should be part of the contract and reviewed when systems or vendors change.
Control provider access first
The outsourced provider may have more technical access than most employees. Require:
- named technician accounts;
- multifactor authentication;
- role-based permissions;
- separate administrative identities;
- restricted remote-support access;
- session and change logging;
- rapid removal when provider staff leave;
- periodic account review;
- customer-owned emergency administrator access.
CISA recommends requiring MFA for email, file storage, remote access and especially privileged or administrative access. Its MFA guidance for businesses also notes that stronger phishing-resistant options provide better protection where available.
Protect Microsoft 365 identity and administration
For many SMEs, Microsoft 365 controls email, files, meetings, identity and external collaboration. Review:
- MFA coverage and exceptions;
- Global Administrator and other privileged roles;
- shared administrator accounts;
- inactive and guest users;
- external sharing;
- mailbox delegation and forwarding;
- legacy authentication;
- application registrations and secrets;
- Conditional Access where licensed and appropriate;
- audit and sign-in review.
The provider should explain which checks are continuous, monthly or event-driven.
Make employee lifecycle a security control
Security gaps often appear when people join, change roles or leave.
A controlled process should include:
- approved identity request;
- role-based license and access profile;
- MFA registration;
- device assignment;
- manager approval for additional access;
- removal of rights no longer needed after a role change;
- account disablement on exit;
- device and authentication-token return;
- mailbox and data ownership transfer;
- closure evidence.
Do not allow HR, managers and IT to assume another team completed the final step.
Maintain a complete endpoint inventory
A security product cannot protect devices that are unknown or not enrolled.
The inventory should show:
- assigned user and location;
- operating-system version;
- encryption status;
- endpoint protection status;
- patch compliance;
- local administrator access;
- last check-in;
- warranty and lifecycle;
- lost, retired or disposed status.
Review unmanaged devices that access email or business files, including personal mobiles and contractor laptops.
Use layered email protection
Email remains a common path for credential theft, fraudulent payment requests and malware. Controls should cover:
- anti-phishing and anti-malware settings;
- domain protections such as SPF, DKIM and DMARC where correctly implemented;
- external-sender identification;
- reporting of suspicious messages;
- executive and finance mailbox protection;
- mailbox forwarding and rule review after suspected compromise;
- user awareness and verification of payment changes;
- incident escalation.
Technology should support, not replace, business verification for bank-account or payment-instruction changes.
Control local administrator and software installation
Permanent local administrator rights make it easier for malware or unapproved applications to alter devices.
Define:
- which roles genuinely require elevated access;
- how temporary elevation is approved;
- approved software catalogue;
- removal of unsupported applications;
- monitoring of unauthorised installations;
- exception review dates.
The provider should not use one shared local administrator password across every device.
Review firewall, VPN and remote access
Network controls should be documented and tied to business need.
Check:
- supported firewall firmware;
- named administrators and MFA;
- internet-exposed services;
- VPN users and expiry;
- vendor and contractor access;
- guest and corporate Wi-Fi separation;
- configuration backup;
- rule review and change approval;
- alert monitoring;
- replacement and support lifecycle.
Remove rules that no longer have an owner or valid requirement.
Make backup difficult to destroy
Backup is part of cybersecurity because ransomware and compromised administrator accounts can affect recovery copies.
Review:
- workloads and Microsoft 365 data protected;
- separation from production credentials;
- MFA for backup administration;
- immutable, offline or separately protected copies where appropriate;
- failed-job alerts;
- retention;
- restore-test evidence;
- isolated recovery procedures;
- business validation.
CISA’s #StopRansomware Guide includes recommendations for maintaining protected backups and preparing recovery as part of resilience.
Patch with risk and evidence
“Automatic updates enabled” is not a complete patching programme.
The provider should report:
- devices and servers in scope;
- supported operating systems;
- critical and overdue updates;
- reboots and maintenance windows;
- failed deployments;
- third-party software coverage;
- firmware and network device updates;
- exceptions and compensating controls.
Test important applications before widespread changes where the risk of disruption is high.
Define security monitoring expectations
Not every SME needs a full security operations centre, but every critical alert needs an owner.
Clarify:
- which products generate alerts;
- who reviews them and during which hours;
- severity definitions;
- customer notification;
- authority to isolate a device or account;
- specialist escalation;
- evidence and incident records;
- monthly reporting.
A tool that sends alerts to an unmonitored mailbox provides limited protection.
Prepare an incident decision tree
For suspected account compromise, malware, ransomware, data exposure or unauthorised access, define:
- how the issue is reported;
- who confirms severity;
- which immediate containment actions are authorised;
- who preserves evidence;
- when specialist response is engaged;
- who informs leadership, legal, insurers or customers where required;
- how recovery is approved;
- how lessons and corrective actions are tracked.
The provider should not make legal or business communication decisions without authority.
Review third-party and subcontractor access
The IT provider may use a remote helpdesk, monitoring company or onsite subcontractor. Ask:
- which subcontractors are used;
- where they operate;
- what customer access they receive;
- how staff are vetted and removed;
- which security requirements apply;
- how incidents are reported;
- how the customer is informed of material changes.
Supply-chain security should be part of provider due diligence and contract review.
Use a management cybersecurity scorecard
| Area | Evidence management should see |
|---|---|
| Identity | MFA coverage, privileged roles, inactive users and exceptions. |
| Endpoints | Known devices, protection, encryption and patch status. |
| Configuration review, reported phishing and compromise response. | |
| Network | Supported devices, rule review, remote access and alerts. |
| Backup | Job status, failed-job action, protected copies and restore tests. |
| Incidents | Timeline, impact, containment, recovery and corrective action. |
| Vendors | Provider access, subcontractors and open supply-chain risks. |
| Governance | Risk owners, deadlines, accepted exceptions and budget decisions. |
NIST Cybersecurity Framework 2.0 provides a high-level structure across Govern, Identify, Protect, Detect, Respond and Recover. The framework can help SMEs organise their desired outcomes without assuming one product or provider solves every area.
The outsourced-IT cybersecurity checklist
- Document shared responsibility for every core control.
- Use named provider accounts with MFA.
- Review Microsoft 365 administrators and exceptions.
- Operate a joiner, mover and leaver process.
- Maintain a complete endpoint inventory.
- Protect email and verify sensitive financial changes.
- Control administrator rights and software.
- Review firewall, VPN and vendor access.
- Protect backups from production compromise.
- Track patch exceptions.
- Assign ownership for every security alert.
- Test the incident decision tree.
- Review subcontractor access.
- Report evidence and open risks to management.
Review exceptions as carefully as controls
Most security environments contain exceptions: an old application cannot support MFA, a specialist vendor needs temporary remote access, a device cannot receive a current update or a shared operational account cannot immediately be removed. The risk is not the existence of every exception; it is allowing exceptions to remain invisible and permanent.
Maintain an exception register containing the affected system, business reason, risk, compensating control, owner, approval and expiry date. Review it during the monthly service meeting. Temporary vendor access should close automatically where possible, unsupported devices should have a replacement plan and policy exclusions should be retested after platform changes.
Verify the provider through evidence
Do not rely only on statements such as “all devices are protected” or “MFA is enabled.” Request evidence appropriate to the service, such as compliance summaries, inactive-user lists, administrator-role reviews, failed backup actions, patch exceptions and incident records. Evidence should protect employee privacy and sensitive configuration while still allowing management to understand whether the agreed controls operate.
A concise monthly pack is usually more valuable than a large technical export. It should highlight exceptions, business impact, actions, owners and decisions required from the customer.
Frequently asked questions
Does outsourced IT include cybersecurity automatically?
No. Routine security tasks may be included, but scope, monitoring hours, specialist response and customer responsibilities must be explicit.
Who owns cybersecurity when IT is outsourced?
The business remains accountable for risk and policy. The provider operates contracted controls and reports evidence and exceptions.
Is MFA necessary for every user?
MFA should be required wherever possible, with highest priority for email, remote access and privileged accounts. Exceptions should be documented and reviewed.
Is antivirus enough?
No. Effective protection also requires identity security, patching, email controls, backup, access governance, monitoring and incident readiness.
What should be reported monthly?
Management should receive concise evidence on identity, endpoints, patching, email, network access, backup, incidents, vendors and open risks.
Security becomes manageable when responsibilities and evidence are visible. Dubai SMEs seeking an operating model that connects user support with identity, endpoint, backup and infrastructure controls can review managed IT services in Dubai.