
Cyber Bytes: Outsourcing Your Cybersecurity and IT Services
Cybersecurity and IT compliance are requirements in today’s business landscape. Criminals target businesses that don’t keep pace with cybersecurity and incident response planning, especially small to midsize companies.
Depending on the scope of a data breach, the direct and indirect costs can impair or bankrupt your business. Cybersecurity and incident response plans (IRPs) are critical to every risk management strategy, but many companies don’t have one.
Common security breaches and costs
According to IBM’s “Cost of a Data Breach Report 2025,” the average worldwide data breach cost $4.44 million in 2024. However, costs surged to $10.22 million in the U.S. in 2025. That’s 9% higher than in 2024. Regulatory fines and detection and escalation costs contributed to the increase. According to the IBM report, the most common attack vectors were:
- Phishing: 16%
- Third-party vendor and supply chain compromise: 15%
- Compromised credentials: 10%
- Insider error: 10%
- System error: 9%
- Vulnerability exploitation*: 9%
- Physical theft or security issue: 9%
- Denial-of-service attack: 12.5%
- Malicious insider attack: 9%
*A zero-day vulnerability is a software security flaw that is unknown to the company or vendor. The vulnerability is open to exploitation until it’s discovered and patched. The Cybersecurity & Infrastructure Security Agency (CISA) records known vulnerabilities. Your IT team should fix these known threats immediately.
Even though malicious insider attacks accounted for 9% of cyberattack types, they were the costliest, at $4.92 million.
The report also showed that security AI and automation continued to drive down breach costs. Since AI tools are a skills multiplier, cybersecurity teams can oversee more systems and react quickly to threats. Businesses using AI and automation as cybersecurity solutions show lower breach costs ($3.62 million) than those that didn’t ($5.52 million).
Businesses with cybersecurity and IRPs also fared better than those without. Regardless of whether you use AI, having an IT team is crucial.
Small businesses are prime targets
Small businesses aren’t immune to cyberattacks; they’re targets. Smaller companies have high-value data that criminals can monetize, like personal information and supply chain credentials. According to a recent Forbes article, small businesses are easy prey because:
- They don’t report cyberattacks to authorities.
- They’re unaware of evolving cyberattack methods.
- They lack advanced cybersecurity.
Forbes reported that 43% of small businesses had no firewall, and 44% believed antivirus solutions were enough to protect them from all types of cyberattacks. The article named common entry points into small-business networks:
- Phishing attacks: 53%
- Unpatched servers or virtual private network (VPN) attacks: 38%
- Credential theft: 29%
To keep pace, business owners are turning to IT vendors and managed security service providers (MSSPs) for IT support and security needs. Here are a few ways to begin your search.
Cybersecurity and data protection: Start somewhere
A cybersecurity plan involves cybersecurity analysis, workflow processes, IRPs and user access restrictions, such as:
- Firewalls
- Secure document disposal
- Software patches
- Ongoing cybersecurity training
- Secure remote and network accessibility
- Multifactor authentication
- Vetting partner networks
- Strong passwords
- Zero-trust network architecture
A word on zero-trust networks
Most cybersecurity experts favor a zero-trust network approach because threats can come from anywhere. Zero trust requires all users to authenticate their credentials, whether they’re inside or outside your business network. They must be authorized and validated at each step before being granted access, or to maintain their access to network applications and data.
A zero-trust security model recognizes that there are multiple ways into a network. Most companies are built on a hybrid network involving local data, cloud data, Internet of Things devices and remote workers. Any one of these points could be the weak link in a cyberattack.
Choose your internal stakeholders before you start a vendor search
Identify key individuals to evaluate cybersecurity needs across your business. If you don’t know your needs, assign specific roles to employees and board members for planning and maintenance.
Think of cybersecurity assignments like you would an internal organization chart or project management team:
| Questions for your internal stakeholders | What the answers can help with |
| Who is responsible for security and operations when outsourcing IT services to an MSSP? | Being clear about expectations involves hashing out the process and assigning clear roles. For example, determine who’s responsible for evaluating the effectiveness of your current cybersecurity solutions, who should research and present alternatives, and who will interview IT service providers. It could be a single person or a small team. |
| What are the most critical assets, and how do you protect them? | Have your team identify all the software (official and unofficial), application programming interfaces (APIs) and plug-ins used at your company. This will give you a clear idea of what you’re dealing with. Some groups use unofficial software, like a graphic design program or an accounting plug-in. Every asset in your company is a potential entry point for a cybercriminal. Unofficial software use opens your company to data breaches. However, if your staff uses unofficial software, ask why. Seek licenses to make it official. Internal conversations like these will give you a window into questions to ask a potential IT service provider later. |
| What should an MSSP provide to demonstrate security controls before you award a contract? | Once you know what needs protecting, you can figure out which IT service providers are a good fit. For example, if you want a provider to use AI-based cybersecurity tools, ask them to explain the systems and the type of oversight they use. |
| What network and system access levels are appropriate for third-party service providers? | Determine how much system access you want to give your potential IT provider. For example, do you have intellectual property, copyrighted materials, or vendor and customer information that they shouldn’t be able to view? |
You might learn a lot about how technology is used at your company, including workarounds and other behaviors that could create security risks. Make it a safe space for stakeholders to discuss concerns freely.
Deciding on an IT vendor or MSSP
Seek an IT vendor or MSSP that understands your operations. It helps if they’ve supported businesses in your industry, but it’s not a deal-breaker. Don’t get overwhelmed and assume you must be a technology genius to interview an IT service company.
Most reputable MSSPs will encourage questions and explain what they offer in layperson’s terms. Tell them if you feel they’re bogging you down with techno jargon. If they continue to talk over your head or shame your tech experience, move on to a new candidate.
An IT vendor will be a member of your business. They’ll have access to your most sensitive resources, which demands trust and transparency. The last thing you want is a condescending tech department you’re afraid to question or contact.
Outsourcing IT services increases your cybersecurity, but it also comes with added risks. Approach outsourcing your IT vendor the same way you’d vet a new business partner or employee:
| Step | Why the step is important |
| Find an IT vendor or MSSP. | Your MSSP is an extension of your business, so they should respect your goals. Look for an MSSP that understands your business growth plan and the types of technology you’ll use to get there. For example, you’ll need aggressive security if your business is transitioning to a self-managed client payment portal. As technology changes, so should your cybersecurity. |
| Ask about AI. | Security automation uses AI and machine learning to eliminate threats before they become breaches. Cybersecurity companies are pairing AI with human IT teams to handle the growing threat landscape, from the Internet of Things to remote workers to hybrid cloud environments. |
| Take multiple bids. | If you have specific IT goals, like a cybersecurity audit or an IT overhaul, ask them to provide cost estimates and rollout timelines in their bid. |
| Review the service contract and scope of work. | Run the contract past your lawyer. Ensure it includes the services you discussed, dates, hourly rates, service locations, their business address and payment terms. |
| Ask around. | Look to your network and trusted business relations for referrals. |
| Get references. | Contact references to learn how the IT company has handled or rehearsed data breaches. If they’ve never rehearsed a data breach with their previous clients, consider moving to the next candidate. It could mean they’re lacking transparency, service and support. |
| Ask for certificates of insurance. | In addition to your own business cyber liability policy, your MSSP needs cyber coverage. Ask us to review the policy for proof of adequate coverage. Cybercriminals target MSSPs, which puts your data at risk. |
| Meet the person in charge of your account. | Some IT vendors use sales staff to pitch their services, so you’ll want to ensure you get along with the team servicing your account. |
| Review their industry knowledge and direction. | An MSSP should recommend ways to implement, maintain and improve your cybersecurity. They should have a well-developed IRP and stay current with cybersecurity trends. |
| Review their IT auditing and incident response testing. | An MSSP should understand your hardware, software and voice systems. They should also be able to test them for efficacy. Based on the results, they should provide you with a report and recommendations for improvement. Visit CISA’s Cybersecurity Incident Response Training page for information on IRPs. Your IT vendor will be involved in answering cyber insurance questionnaires. You’ll need these reports when applying for your cyber liability policy. |
Don’t navigate the cybersecurity landscape alone
Most insurance companies will evaluate your cybersecurity, IRPs, data collection and employee training programs before issuing you a policy.
With an MSSP team and robust testing and training initiatives, you could increase your chances of getting a policy with lower premiums.
Assume there’s a data flavor for every cybercriminal, and your business could be it. Stay vigilant for potential insider and outsider threats to your system, and enlist the help of a cybersecurity team.

