Mind sharing a clarification on your understanding of "common" and "big"?
Also, companies host for example an Exchange server on prem; and guess, what it connects to? Why you can usually access account at outlook.com?
I am sure MS employees need to tell themselves that to sleep well. The statement itself doesn't seem to hold much epistemological value above that though.
Absolutely there are specific companies or industries where they think the risk is too great but for many, outsourcing the process is either the same or less risk then doing it all inhouse.