BPOs Can’t Delay Bolstering Cybersecurity Capabilities

July 22, 2026

No one should underestimate the extent to which digital crime continues to menace businesses across sectors.  High profile hacks are regularly reported, and the impact on individuals affected is so great that it is nearly impossible to quantify.  It was with this backdrop that Huntress and Ryan Strategic Advisory recently hosted a thought-leadership lunch in London on the cybersecurity dynamic for BPO operators, to discuss the challenges they face in this regard.  In no specific order, the following were the 5 key takeaways from this gathering, which assembled a dozen outsourcing leaders from across Europe.

  • BPOs are an attractive target for bad actors – cybercriminals see outsourcers as a lucrative opportunity for nefarious activity. As an integral part of an enterprise’s supply chain, CX service providers house a treasure trove of consumer and business data that hackers would love to obtain, either for their own use or to sell to other criminals.  Relatively speaking, very few third-party suppliers have as much sensitive information potentially stored in their data repositories.  This makes BPO players an incredibly rich target and unless these organizations aggressively arm themselves, the chances of a hack are high.
  • Each BPO needs a clear cybersecurity owner – an important point of discussion at the recent lunch hosted by Huntress and Ryan Strategic Advisory was the requirement for outsourcing operators to have a point where the proverbial cybersecurity buck stops. In 2026, no matter the size of the provider, it is not feasible to have this function run under peripherally under another division such as compliance or IT, nor is it practical for it to be governed by committee.  Rather, forward-looking BPO firms must identify a single point of responsibility for cybersecurity and provide them with the resources needed to maximize their resilience in face of ever evolving cyberthreats.
  • Clients expect their BPO partners to have the best cybersecurity – in today’s procurement environment, possessing top-line data protection is a must among enterprise executives when selecting an outsourcer. This was highlighted in the Ryan Strategic Advisory 2026 CX Technology and Global Services Survey, which sounded over 800 captive customer management leaders across Western Europe, North America and Asia-Pacific.  Among the most provocative results was that when picking a third-party CX services partner, buyers place the highest priority on those possessing the most cutting-edge cybersecurity capabilities – not cheap price points, not the latest AI flavour of the month – they want their data locked down and safe.  BPOs that don’t get the memo will simply be passed over by existing and prospective clients.
  • Access to leadingedge cybersecurity is tough going for growing BPOs – one of the most important messages resonating from the recent BPO cybersecurity lunch was both encouraging and worrying. On the plus side, there is a clear desire on the part of outsourcers to make robust, comprehensive investments in their cybersecurity capabilities; on the negative, there is a near unanimous view that to date, most vendors of these solutions are almost exclusively concentrating on global clients, rendering the right info-sec investments out of reach for growing CX services players.  Emerging and mid-sized outsourcers are anxious to find cybersecurity providers that can offer flexible pricing mechanisms and scalable tools that can meet the needs of rapidly growing third-party operators.
  • There is a significant cost for BPOs that underinvest in cybersecurity – it may sound redundant, but it is worth repeating that any outsourcer, no matter the scale, which chooses to skimp on cybersecurity can only blame themselves when they are hacked. Whether they are hit with ransomware, become victim of a data breach or fall foul to an identity / account takeover attack, the impact on a BPO over the long term can be crippling.  Finding a partner that has not just the right tools for a growing BPO, but the know-how to deploy these solutions is crucial for long-term business continuity and commercial viability.  Outsourcers that believe they can do better in the domain of cybersecurity have no time to waste in properly equipping themselves.

Image sourced from Prachatai under relevant creative commons license