The structure of IT security teams varies across different businesses. Of those that have a dedicated in-house security team, many roles are involved – CISO, risk and compliance groups, security ops centre, threat intelligence teams and malware analysis teams to name a few. This complex division of responsibilities may work harmoniously, but what happens when one element fails? In-house security teams involve many roles – CISO, risk and compliance groups, security ops centre, threat intelligence teams and malware analysis teams to name a few. This complex division of responsibilities may work harmoniously, but what happens when one element fails? Scott Dodds of Ultima MSP argues that outsourcing a business's security function to a managed service provider (MSP) could provide the ability to deliver greater compliance and greater efficiency of cyber security solutions. But how easy is it to effectively outsource the security function? © 2021 Elsevier Ltd