If there's one topic that is likely to make any CIO's or IT Manager's wallet hurt, it's information security. With all the media coverage lately on data theft, credit card theft, Personally Identifiable Information (PII) theft and identity theft, every organisation from the sole proprietorship to the massive international megacorp to the critical government agency knows that they need it and suspects that they lack it. It's one thing when a small-town restaurant's Twitter account gets hacked, but it's something else entirely when a government agency charged with performing background checks for security clearances cannot keep the PII of its investigation subjects secure.
And while the megacorps can call on mega-consultancies, and the big government agencies can call on… well, let's hope they figure that one out… who are the smaller organisations supposed to call upon for help? Information security is a specialty trade and experts do not come cheaply. With so much demand and relatively little supply, the market is primed for a rise in specialty firms and independent consultants offering Security as a Service (SaaS), at great savings. These may be tempting, especially when the latest hacks are front page news, but small to medium sized organisations should think before they act. Here's what you should consider.
There are no silver bullets
First and foremost, there are no silver bullets, quick fixes or easy outs here. Security is a mindset, a way of life, and must be pervasive throughout all your information systems, from logons through drive encryption to application hardening and secure remote access, and dozens of other things as well. If you are looking to ensure your information technology infrastructure is secure, you need to make sure that the consultant or firm you choose to assist you has practical experience with all of your systems.
One size does not fit all
Two organisations with the same number of employees, the same annual revenues and the same number of systems will not have the same needs. You may want to go with a fixed fee engagement, but unless the provider is so large and has such a mark up on services that they can afford a variance from one project to the next, expect the really good ones to quote on time and materials. Security is best when it is layered, and security assessments have to peel back the layers to truly understand what is going on. Until you get three layers down, you won't know what to expect at the fourth layer, so plan for this to cost what it costs.
Expertise is not gained overnight
A lot of consultants may choose to hang their shingle out to meet this rising demand, and may be relatively new working for themselves, but they should have years of industry experience working for companies as security experts in order to be truly qualified to help you with your security. Ask questions, look at resumes, and be sure that the professionals providing your services truly are professional.
Certifications are good, but references are better
There are lots of security certifications on the market, and many are truly challenging to obtain and maintain, but just because someone can pass a test, doesn't mean they are a security expert. Ask for references from previous customers or co-workers and take the time to check out the references before selecting a provider. Unless you truly are their first customer, they should have previous customers willing to take a few minutes to talk with you about their experiences.
This is not a one-time thing
Security assessments, vulnerability scanning, penetration testing, system hardening…these are perpetual needs your information technology infrastructure will have forever. Don't look at a security assessment engagement as a one-time thing. You go to your doctor for an annual check up (I hope!) and you should plan on getting your security posture evaluated at least annually as well. In between those annual full check ups, you should consider a monthly vulnerability assessment just to help make sure you are keeping up with your patching and system configurations.
Does it make sense to subscribe to SaaS or bring expertise in-house?
You could contract with a Security as a Service provider to provide you with regular security services, or you could perhaps have them help your own IT team to deploy in-house systems for vulnerability assessments and patch management, and then use your provider when needed for major projects, upgrades, or annual check ups. If your IT team has the capacity to take on the additional work needed for security, get them the right tools and training and let them take care of it. Get an annual audit to be sure, and again, consider an external monthly vulnerability scan to make sure nothing was missed. But if you are the IT team, as well as the sales manager and delivery driver, you probably already work 25 hours a day, and may need to rely upon the pros going forward. Go with what makes sense for your business and your budget, but remember that a single security incident can put you out of business, so don't leave this to chance!
Information security is critical for any organisation with any IT at all… even if you run your entire business from your mobile phone, imagine what damage would be done if your email was hacked or your credit card processing system was compromised and your customers found bogus charges on their accounts. For any business with any presence online, ensuring your systems are secure and remain so is critical to ensuring you stay in business. There will be many independent consultants and security firms offering to help you do just that, for the right price of course. Ensuring you get the right service for your needs is going to be the right way to help keep your business going strong, staying secure, and remaining trusted by your customers. Feeling social? Follow us on Twitter and LinkedIn Now!