Hiring Bodyguards: The Art of Outsourcing Security Management

author-image
DQChannels Bureau
New Update

Security breaches are on
the rise and affect both large and small enterprises, though in case
of the latter, it mostly remains unreported. With the growing
competition, there is a greater need to share systems and data with
employees, business, and potential customers. Thus there is a growing
dependency on internet, exposing the network to various attacks like
Denial of Service (DOS), theft of proprietary information, financial
fraud, and sabotage or system penetration causing breakdowns, which
could sometimes be fatal to the business.

Advertisment

In today's sophisticated
environment, traditional security controls are not enough to protect
critical assets. Constantly evolving technologies and attack
techniques make security a moving target, exposing the enterprise to
new risks almost daily. As a result, it is increasingly difficult to
defend against emerging threats while still providing users with
unfettered access to resources. Under such conditions, it becomes
necessary for organizations to secure their systems by deploying a
set of IT policies for use and monitoring of data, devices, and
appliances to connect and protect systems, provide end-to-end
security solutions. Effective security helps maintain the integrity
of valuable assets, enables compliance with industry regulations, and
helps ensure the integrity of a trusted brand image and sustain
business continuity. But providing an effective level of security
requires state-of-the-art technology, experienced personnel, proven
processes, and continuous threat intelligence that few organizations
possess.

To make good decisions and
protect information assets, companies must understand what is
happening both inside and outside the corporate network. Therefore,
organizations often find themselves choosing between two
options-managing security in-house, or outsourcing either all or some
security management to a managed security services provider (MSSP).
Under both situations, there is round- heclock management and
maintenance of the network from various attacks. However outsourcing
such services would be an apt option for SMEs as it reduces overhead
costs and improves operational efficiency and enhances system
productivity. Gartner defines 'security as a service' as 'security
controls that are owned, delivered, and managed remotely by one or
more providers. The provider delivers the security function based on
a shared set of security technology and data definitions that are
consumed in a one-to-many model by all contracted customers anytime
on a pay-for-use basis, or as a subscription based on use metrics.'
MSSs can be defined as 'security as a service where an MSSP selects,
owns, and manages the technology that delivers the security
function.' This definition holds true whether the controls are based
in the cloud, in the service provider's network, or on the customer's
premises.

Today, managed security
services (MSS) offerings exist in various forms, from pure system
management to more sophisticated log analysis using a number of
delivery mechanisms, from software-as-a-service (SaaS) and cloud
services to on-premise device monitoring and management. This could
spell big opportunities for solutions providers (SPs) catering to the
SMB and enterprise segment. Sensing this, many SPs and their vendors
are working toward setting up their MSS offerings. Sanjiv Patki,
global VP, Allied Digital, a company which is in this space of
business of providing managed security services since 2007, and which
has set up its Security Operations Center(SOC) said, “Amongst the
market we operate in, we have seen that India has been a slow starter
in uptaking these services, as companies seem to have a false sense
of confidence that their network infrastructure is impregnable.
However, in matured markets, we are seeing a lot of traction in MSS
space. Most of our customers are from matured market. Even among
those who have subscribed for these services, have done it more from
a compliance perspective. Hence, it is difficult for IT managers to
see the full value of security services. However, we are quite
bullish about the Indian market now and we feel that by the year
2012, the necessity of security services will be understood by Indian
CIOs and a lot of business is expected during this period.”

Advertisment

GRADUALLY MOVING style="font-weight: bold;">

Although the concept of
MSS in India is still at a very nascent stage, security vendors like
McAfee looks skeptical on the uptake of MSS. Ambarish Deshpande,
director, channel and alliances and mid- market, South Asia, McAfee
said, “Managed security is all about outsourcing the security of a
company's infrastructure to a third party vendor to get better
visibility and control on companies' security. While globally this is
a growing trend, in India, I personally feel that this needs a much
bigger thrust to succeed. This is mainly due to lack of regulatory
guidelines and controls. We've seen few companies opting for managed
security services but they are not large in volume.” Nevertheless,
the growth of MSS globally is picking up at much faster rate.
According to a global strategic business report titled 'Managed
Security Services'-the global network security market is expected to
reach $8.4 bn by 2015. Another research study expects the managed
security services market to grow about 13% in 2011, and to reach
$16.8 bn by 2015, with the strongest growth coming from the SaaS
segment.

Hemal Patel, CEO,
Elitecore Technologies strongly feel that MSS is the future and India
has a fast market uptake of MSS. According to our estimates, the
market is growing at a rate of 25% on a y-o-y basis. The Indian
industry has reached the level where organizations are increasingly
going for the MSS model to improve their security posture and
reducing their operational expenditure.” Cyberoam is currently in
the process of having partnerships with a nationwide network of MSSPs
to sell CR range of Unified Threat Management (UTM) appliances for
their enterprise clients. The company is in the process of appointing
Managed Security Services Provider (MSSPs) as a focused initiative to
drive more opportunity for partners. The objective is to provide
affordable UTM as a service to midmarket organizations through
partners. Cyberoam believes that it can rake in good revenues through
the MSS model. It has been targeting all verticals including
education, manufacturing, IT, and retail, etc, through the MSSP
route.

SHIFT FROM IN-HOUSE TO
OUTSOURCED MODEL


India has been slow in
adopting MSS, but because of the building awareness and presence of
drivers that accelerate the adoption of MSS, India is forging ahead
in this space with increased momentum. Enterprises have begun to
recognize information security as an independent function rendering
lot of space and ease for the adoption of MSS. Also, continuing
expansion of infrastructure and growing business requirements makes a
strong security management system a must. This makes the current
scenario an ideal time to switch from an in-house model to an
outsourced model, the 'Managed Security Services'.

Advertisment

The MSS model helps
organizations focus on their key business with the comfort that
security is being managed by the experts. According to Springboard
Research, Indian enterprises are increasingly accepting managed
services, as the need to reduce overall costs of IT functions becomes
critical. Enterprises are under intense pressure to increase
profitability and show higher value to stakeholders. While IT
operations continue to be a critical element in the overall corporate
spending, there is an increasing pressure on CIOs to justify
investments and fully utilize current IT facilities. According to
Sumeet Parashar, India Lead global security solutions, CSC, a company
that provides enterprise-class cybersecurity services and has evolved
from over 35 years of experience, said, “Indian firms have started
adopting managed security services over the past few years, with the
scope of uptake still being very large. Enterprises are increasingly
becoming security conscious in view of widely reported global
security breaches. Julian Assange of Wikileaks today is a household
name because of breach of security. Such cases coupled with an all
time high Advanced Persistent Threats (APTs) have forced
organizations to reconsider their security arrangements and think on
the lines of threat intelligence.” In this global village, no
corporate is any more isolated and each one of them have started
realizing that they are exposed to national and international
threats. There is increasing awareness among the enterprises that
they require specialized security experts for proper protection
against ever-changing threats to their organization. Add to this, the
evolving regulatory frameworks in key sectors such as banking and
telecom, (RBI guidelines for banks and DoT guidelines, etc) are
driving the need for organizations to rapidly adopt security best
practices. Patel pointed out, “Many organizations feel the need for
a handholding model when it comes to the best security decisions
relevant to them. This has led to the rise of a number of managed
security players in the Indian market that are operating in both the
SMB and mid-markets, offering tailor-made solutions as per the threat
climate affecting their clients. Most of these players work to
providing security based on a per month subscription model at
customer site premise. Another factor pushing the trend is the need
for greater vendor accountability.” Just because a company is
smaller does not necessarily mean it is safer.

In fact, the larger the
organization greater are the technical resources and higher funds are
available to invest in security. Smaller organizations, on the other
hand,are more vulnerable to hacking due to lack of information and
expertise to implement sufficient protection mechanisms or resources
to monitor their network 24x7. In addition, hackers are aware that
SMEs do not have legal resources to report and recover damage caused.
For these reasons, SMEs must take a variety of security precautions
to protect their network, and managed security service is the best
solution to address their issue of robust security at affordable
costs, feels Ravishankar, CEO of Nevales Networks.

“Enterprises need to
recognize these threats and eradicate them using apt security
expertise. However, it may not always be efficient to maintain an
adequate staff of trained personnel inhouse, while also staying
abreast of the ever-evolving technology and threat landscape. All
these factors contribute to the increasing demand for managed
security services in India, since it helps them identify threats and
prevent sensitive information from being compromised,” says Ajay
Goel, MD, India & SAARC, Symantec, it has established a Security
Operations Center (SOC) in Chennai-one of four globally-which
delivers world-class managed security services to customers in India
and around the world. It analyzes more than 10 bn logs worldwide each
day toprovide enterprise-wide protection and help customers bolster
defenses and respond to new threats as they emerge. Experts believe
that the inability of companies to attract and retain talent is
another big driver for outsourcing security management. Even large
organizations are today finding it difficult to retain security
experts, as they are not able to keep such experts engaged over a
period of time as well as not able to pay the compensation demanded
by these experts. What companies then turn to is real-time security
monitoring and management options at a fraction of the cost of
inhouse solutions.

Advertisment

OPPORTUNITIES FOR MSSPs

With managed security
services, MSSPs can generate new opportunities by using their
existing infrastructure to increase profitability, reduce price based
competition, and increase customer base and loyalty. Once security
services are in place, instead of simply providing the solution and
moving on, the serviceprovider becomes an indispensable business
partner that helps customers manage their risks and also tap into new
markets. Solution providers like Cyberoam see MSS partners as a
cost-effective route to reach enterprise customers in several
segments which are driven by considerations of investment, absence of
quality manpower, and the need to gain the advice of security
experts, who are the best in the industry.

According to Patki of
Allied Digital, one of the major MSSP in Mumbai which has a joint
venture with one of the Singapore based firm e-Cops, said, “We are
now seeing a lot of traction not only in the perimeter security but
also in the end point security space. More and more CIOs have
realized benefits from these services. This opens up a lot of
opportunities in security space. Moreover, other factors like
compliance requirements and cloud computing are also driving the
growth. MSS enables service providers like us to offer managed
security services to their customers without any upfront investment,
or the need to develop specialized in-house security expertise.” He
also added, “For MSSP there needs to be a good SOC available with
right toolsets. The toolset would include vulnerability assessment,
penetration testing, log monitoring tool, website monitoring tool,
etc. We need right processes in place to deliver services to
customers. Last but not the least, people with security background
and who follow process, need to be available. Speaking to MN Kutty
Nair, chairman and MD, MIEL e-Security, a security SP from Mumbai,
said, “Our company has been offering MSS since 2004, and we have
seen a significant rise in demand in the last 3 years. The key role
of an MSSP is to ensure that the quality and efficiency of the
service is maintained to the highest level. In order to ensure this,
an MSSP should conduct internal audits on their own staff and setup
on a timely basis.” Seeing the response, the company is planning to
offer almost all their services remotely and do away with the onsite
model. It is expanding security operation center team and
infrastructure to be able to better manage a large number of clients
centrally.

NEED FOR SKILLED MSSP
AND SLAs


There is still a lack of
information with regard to the costs entailed by serious data
breaches and the many benefits of outsourcing security to a good
MSSP. In addition to that, scalability, automation issues, lack of
investments in regional SOCs, and localization of support are
hindering the growth of this market. Patel of Elitecore Technologies
suggested, “First and foremost, as a UTM vendor, we can say that
MSSPs selling UTM appliances to their customers, must have
well-trained security experts. However, mid-sized MSSPs are expected
to face stiff competition from the larger national MSSPs such as
Wipro, HCL or even TCS which set up the practice a few years back.
Some MSSPs feel that the most common issue hampering the growth of
MSS has more to do with the education of SMBs about many benefits and
cost savings. SPs report that there is also reluctance, especially
among SMBs, to outsource services in a sensitive area.

Advertisment

Effective security
management requires a combination of skilled personnel, best practice
processes, and state-of-the-art technology. “A thorough cost
analysis is important when evaluating a MSSP, but it comprises only
part of the total analysis. Levels of staffing, security expertise,
specialized skills that may only exist in-house, and existing
security investments are other important considerations,” said Goel
of Symantec. “Deciding between leveraging in-house security
resources and partnering with a MSSP requires research and budgetary
scrutiny, for both the short and long term. Ultimately, organizations
should choose the option that will allow them to maintain a strong
security posture and enables them to pursue their primary mission,”
mentioned Kartik Shahani, country manager, RSA India and Saarc.

“An MSSP must have
extensive security knowledge along with competent team of security
consultants and engineers who can understand and assist an
organization with design and rollout of their security strategy.
Direct support is provided through Security Operations Centers (SOCs)
where networks are monitored 24x7 and security data is processed and
stored. The model needs to be resilient with full fail-over
capability,” said Ravishankar of Nevales Networks. Lucia Mikasa,
senior director, marketing, Narus also added, “Some of the skills
required to make the best use of MSS are to have necessary skills and
knowledge in the security-related network services area such as DoS,
DDoS detection and blocking, spam blocking, intrusion detection,
firewall management, Virtual Private Network (VPN) management.” For
a service provider building proper Serve level agreement (SLAs) is of
paramount importance. In absence of SLAs, it would become impossible
to measure the performance of the provider. Hence any price agreed at
the time of signing the agreement becomes impossible to justify on
both the sides. Having established the need for SLAs is the starting
point, however these SLAs need to be properly framed, and timelines
around SLA need to be properly defined.

SET OF CHALLENGES FOR
MSSPs


While MSS is undoubtedly a
big opportunity, it has its share of challenges too. “Low awareness
of the service is one of the major obstacles that we face. Customers
are also quite conservative, and are often apprehensive about the
security and privacy of their confidential data,” Patki
highlighted. MSSPs face a myriad of technical challenges in the
infrastructure they develop, the tools they employ, and the processes
adopted to drive services. There are also numerous business
challenges that make it difficult to provide the right services at
the right time and for the right cost. These issues can pose barriers
to entry into the market and limit profitability if not addressed
adequately. Scalability, automation, internal processes and
professional expertise are often cited as the most significant
technical issues. MSSPs often face problems when scaling their
business, usually because the core infrastructure and technical
issues mentioned above. Another entry barrier that MSSP face is the
syndrome of 'Seeing is believing'.

Advertisment

However there is nothing
to show at the start of the service and that in itself becomes a huge
entry barrier. Lastly, it is also critical that an organization
specify its security requirements and require candidate MSSPs to
demonstrate their ability to meet them, both as part of evaluation
and selection and while providing ongoing services.

CONCLUSION

With the increase in cost
of owning an integrated solution and maintaining the same, large
corporates in India are opening up to the option of outsourcing the
solution to service providers. Services like hosted secured email
security solution, managed authentication solution,compliance, being
able to scale up and down basis fluctuating requirements and most
importantly, the Unit base Pricing model have accelerated the trend
in the security space. Enterprises in India are foremost in the world
in adopting IT services, however, they are now gearing up in security
space as well. With e-governance taking priority in the coming years,
compliance services are expected to take importance. Although the
organization still owns information security risk and business risk,
contracting with an MSSP allows it to share risk management and
mitigation approaches.