
ITCC Advantage – A CIO’s Perspective on Secure Outsourcing
Security is a critical part of any outsourcing decision, from data protection and compliance to threat detection and incident response. At Emapta, these capabilities come together through the IT Command Center (ITCC), which centralizes security, infrastructure, and support across global operations.
In this Q&A, Emapta’s Chief Information Officer Henry Vassall Jones draws on 15+ years of IT experience and his role leading the company’s digital-first technology and transformation strategy to share his perspective on what secure outsourcing should involve.
He also explains the thinking behind the ITCC and how its integrated approach strengthens visibility, response, and operational resilience.
“Few providers can show you a complete set of certifications, effective implementation of tools and controls with verified compliance, and a dedicated IT Command Center watching, correlating and responding in real time, with a single view across their global operations. That is the difference between claiming security and proving it.”
Henry Vassall Jones, CIO at Emapta
Beyond Security Claims: What Providers Need to Demonstrate
As outsourcing takes on more business-critical work, security has become a bigger part of how companies evaluate potential partners. The challenge is that many providers can point to certifications or policies, but as Henry explains, those alone do not always show how security is managed day to day or how prepared a provider is when something goes wrong.
Q: What proof should a genuinely secure provider be able to show an outsourcing client before they even ask?
Henry: “A provider that can prove its security posture will show you the proof before you ask for it. That starts with internationally recognized certifications and attestations that are independently validated rather than self-declared.
Emapta holds ISO 27001, ISO 27701, PCI-DSS and SOC 2, and delivers a secure data processing environment compliant with HIPAA, GDPR and APP standards. It extends to transparency through a public trust center that gives clients a live view of compliance posture and control status rather than a claim on a slide.”
Q: Aside from certifications, what else signals that a provider takes security seriously?
Henry: “Beyond the certifications, look for a dedicated internal security function with its own leadership and accountability, rather than security folded into IT, and security service packages shaped to the client’s industry and operating environment, for compliance from day one.”
The strongest signal of all is how a provider engages at the outset. A partner that runs a joint security and privacy impact assessment during onboarding, then builds a mutual action plan to harden controls on both sides, is demonstrating the effectiveness of security program in practice.
Q: What should leaders ask about when it comes to data protection, access, and governance?
Henry: “Ask whether the provider holds certifications or attestations and ask to see them.
ISO, SOC and PCI-DSS signal that a provider has understood the security risks inherent in its business model and taken deliberate action to reduce them to a managed level.
Ask what security policies and controls deliver a secure data processing environment for your team, and how those controls are enforced rather than documented. Establish where your data resides, who can access it, and how that access is governed and logged.”
Q: How can you gauge whether a provider is ready for a security incident?
Henry: “Test the provider’s readiness for the moment things go wrong. Ask about their incident response process and, specifically, their breach notification timeline. A provider that answers these clearly and without hesitation is one that has thought about your data before you handed it over.”
Q: What should you check on a site visit?
Henry: “Physical security deserves the same scrutiny. On a site visit, verify the basics are in place, security guards, biometric access, CCTV and guest registration, and watch for shared logins or unmanaged and personal devices being used to access client data, all of which point to weak operational discipline.”
Q: What are the clearest red flags in how a provider talks about security?
Henry: “The clearest warning sign is a provider that describes its security but cannot back it up with evidence and artefacts, whether that means certifications it cannot produce or controls it cannot demonstrate.
Be wary when security sits inside IT with no independent function or clear line of accountability, because it usually means no one owns it fully.
Vague answers on incident response, or the absence of a committed breach notification timeline, tell you the provider has not rehearsed the moment that matters most.”
Any single flag warrants deeper due diligence. Where several appear together, keep probing until you have the evidence and artefacts needed to independently validate their security claims.
How Emapta’s IT Command Center Powers Secure Global Operations
For companies outsourcing critical functions, the question is not only whether a provider has the right credentials, but whether its operating environment is built to support secure, reliable delivery at scale. Henry’s perspective brings that into focus through Emapta’s ITCC, which plays a central role in how the company puts security into practice.
Q: How does Emapta’s approach to data security and compliance differ from that of a typical outsourcing provider?
Henry: “Security at Emapta is a core service, not a back office or IT function. It has its own leadership, certifications and accountability.
The distinction is not the certifications we hold, it is that they sit on top of an operating model that is secure by design rather than one that bolts security on afterwards.”
Discover Emapta’s Security Capabilities
Learn how we help safeguard sensitive financial data with security built into the people, processes, and infrastructure behind our outsourcing solutions.
Q: How does the ITCC strengthen Emapta’s commitment to keeping its clients’ operations secure?
Henry: “Emapta’s model is resilient by design,16 Philippine and four global service delivery centers, with redundant connectivity, secure VLANs, network access control enforced through 802.1x, and secure endpoint standard operating environments with real-time, end-to-end monitoring across our entire ecosystem.
We don’t treat compliance as a certificate on the wall. It is a living control set, reviewed regularly and evolved as the organization changes.
The IT Command Center is where that architecture becomes an operational advantage. Operating 24x7x365, it brings the Network Operations Center, Security Operations Center and Remote Desktop Support into a single multi-disciplinary fusion centre rather than three functions running in separate silos.”
Q: What is the value of having a dedicated IT and security facility in an outsourcing environment?
Henry: “Underpinning all of it is centralization. When security, infrastructure and support teams work from a central facility, with real-time intelligence and alerting feeds, events are correlated fast across every system and service-impacting incidents are contained before they reach clients.
That matters because real incidents rarely announce themselves cleanly as a network issue, a security issue or a service ticket.”
Correlating network anomalies, security alerts and service tickets in the same room cuts detection-to-response times to minutes. Governance tightens because oversight of infrastructure, security and support now sits under one command structure instead of three reporting lines.
Q: “How does Emapta make secure collaboration practical rather than restrictive?”
Henry: “The good news is that modern technology makes strong data protection and easy collaboration entirely compatible. Most enterprise platforms carry security capability built in that, configured correctly, prevents data leakage without slowing anyone down.
Emapta’s IT engagement lead works through these settings with each client during onboarding and enables them against your specific requirements, so teams collaborate freely inside an environment that is controlled by design.”
Scaling Global Teams Without Scaling Risk
As offshore and nearshore teams grow, security has to keep pace without creating new gaps or adding unnecessary complexity. Henry shares how Emapta approaches that challenge by designing security to scale with the team, supported by consistent controls, specialist expertise, and centralized oversight.
Q: How should security be designed to scale with a growing team?
Henry: “Look for security that scales by design rather than by headcount. The measure is defense in depth, layered and overlapping controls so that no single failure exposes data, applied consistently whether a team is five people or five hundred.
Emapta builds this across the stack. Identity and access are governed by least privilege, multi-factor authentication and role-based access, provisioned automatically as teams expand so that growth never outpaces control.”
Q: What keeps security controls consistent as headcount increases?
Henry: “Every endpoint is a managed, hardened device with endpoint detection and response. The network is segmented with monitored egress across all delivery centres, and data is encrypted in transit and at rest with data loss prevention tuned to the client’s environment.
Tying it together is centralized monitoring through the IT Command Center, so visibility and event correlation hold steady as the estate grows.”
The principle is straightforward: adding people should never mean adding risk, because every new team member inherits the same posture as the first.
Q: Why does secure outsourcing require specialist expertise?
Henry: “Consider the Olympics. No country sends a single athlete to compete in all sports. They develop specialists, each trained to be the best in the world at their one discipline.
That conviction shows up as dedicated security infrastructure, monitoring and governance: a team of specialists each owning their own domain, rather than a stretched IT generalist covering all three between competing priorities.”
Finding an outsourcing partner that shares the same conviction, one that has made the investment in the people, technology and process to design, implement and operate security at a global scale, is what separates a provider that hopes it is secure from one that is built to be secure.
A Core Capability, A Greater Commitment
For Emapta, security goes beyond meeting outsourcing requirements. It means making the investments in people, infrastructure, and oversight needed to protect what clients entrust to Emapta and support them as they grow.
As Henry’s insights make clear, the ITCC is part of that broader commitment. It reflects an approach where security is treated as a core capability, helping make outsourcing more secure, resilient, and dependable at scale.
Strengthen Your Global Team’s Security Posture
Learn how Emapta helps safeguard sensitive financial data with security built into the people, processes, and infrastructure behind our outsourcing solutions.



