Should IT Security Be Outsourced? Georgia

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

Local Companies

Infinity Network Solutions
478-475-9500
93 Gateway Drive
Macon, GA
EDTS, LLC
706-722-6604
933 Broad Street
Augusta, GA
US Small Business Admin (Score)
(706) 279-3383
524 Holiday Ave
Dalton, GA
Manhattan Associates
(770) 955-1365
3101 Towercreek Pkwy SE Ste 300
Atlanta, GA
Horrigan George R
(770) 642-4220
10902 Crabapple Rd
Roswell, GA
Apiscor Inc
(770) 614-4656
4860 S Lee St
Buford, GA
The Solution Center
(404) 705-8668
310 Sologne Ct NW
Atlanta, GA
Redland Holding Llc
(478) 475-4909
5400 Riverside Dr
MacOn, GA
Hq Consulting Inc
(404) 243-4404
4030 Sweetwater Pkwy
Ellenwood, GA
Intellectual Capital Consulting Inc
(678) 797-5331
61 Whitlock Sq SW
Marietta, GA



By Renee Oricchio

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

"Always retain what is required to protect the brand," says Paul Roehrig, a principal analyst from Forrester Research, who says outsourcing security can be appropriate, but proceed with caution.

Look no further than the story of TJX, the national retailer that owns such chains as T.J. Maxx, HomeGoods, Marshalls and Bob's Stores. In January of 2007, TJX had to publicly admit the most sensitive part of its network had been hacked, exposing the numbers of more than 45 million customer debit and credit cards. In the wake of what is considered to be the worst breach of consumer data ever, dozens of banks were forced to cancel and reissue millions of cards, while TJX faced countless lawsuits and relentless bad press.

"TJX is the poster child that illustrates the bigger they are, the harder they fall," says Ben Rothke, a senior security consultant for the security firm BT INS.

While some IT managers may see TJX as a cautionary tale to keep something as important as network security in-house, Rothke believes the TJX story actually makes a compelling case to do the very opposite.

"When hackers stole customer data from TJX, what made matters worse is that it went on for so long undetected, and once identified, they were slow to tell clients," says Rothke. He adds that most IT departments are notoriously understaffed and underbudgeted when it comes to security.

Here are some of the security functions that could be outsourced in large organizations:

  • Intrusion detection Intrusion detection (IDS) "takes a certain set of protocols and expertise to understand. For most IT departments it's not a core competency," says Rothke. For CIOs who don't already have IDS technology deployed, it can't be done overnight either. The right IDS vendor will already have an infrastructure in place, making rapid implementation possible.
  • Firewall security This, too, is its own discipline, troubleshooting the efficacy of the network firewall or firewalls. What's the firewall protecting? Where are the holes? And how are they to be plugged? Companies need a vendor that understands the nature of rule changes, documents those changes as they happen, and offers 24/7 support.
  • Incident response While intrusion detection is all about discovering a breach when it happens, incident response is all about having the right protocols in place to react. Again, looking back at the TJX case, two of the biggest mistakes the company made that magnified the disaster were the inability to realize there had been a breach going on for months undetected, as well as their slow reaction alerting customers and the public in the aftermath.
  • Forensics How did the breach happen? The kind of security expert that keeps vigil over the network is not necessarily the same person to play detective once the damage has been done. To date, no one has definitively figured out how the TJX breach happened or who was directly responsible. The company suspects wireless transmissions used out of two Miami stores were hacked. With an outside forensics expert, there is the added benefit of third-party objectivity and no self-interest to cover up findings, experts say.
  • Vulnerability scanning The other kind of security expert needed to protect the network is one who can audit and aggregate the risks in all of the above areas and implement routine testing.

While these are the most popular areas of expertise to outsource, Roehrig draws the line between what should stay in-house and what can go out of house more simply.

"Outsourcing can be a great solution for implementation and support, but architecture and setting security policies should stay within the firm," he says.

Outsourcing security: the rules of the road
"If done right, the benefits of outsourcing security are compelling. If done wrong, the risks can be significant," says Rothke.

Here are some strategies to make outsourcing work:

  • Find a good match There are consulting groups that can offer a team of experts to cover all those specific areas of concern: intrusion detection, firewall security, incident response, forensics and vulnerability scanning. CIOs would be wise to assess in advance which of those areas need outside expertise and whether it's better to have one vendor handling everything, or instead compartmentalizing certain areas with multiple vendors.
  • Appoint an in-house liaison to manage the relationship Vendor management by an insider is key. At least one person from the IT department needs to monitor the relationship explaining the needs of the business and its culture to the security consultant.
  • Don't be cheap The right person or firm is not likely to be the most affordable solution. Rothke warns there are plenty of "Mom and Pop" security firms out there. The good ones are a rare commodity and charge accordingly. Plan on paying for quality.

However a CIO decides to handle network security, Rothke offers this final piece of advice: "Hardware's cheap, bandwidth is cheap, contractors in India are cheap. But lawyers are expensive."

Renee Oricchio is a freelance writer in Norwalk, Conn. For the past 20 years, she has been writing and producing news segments about technology and business for CNN, MSNBC, Ziff-Davis, CNET and a variety of Silicon Valley-based local news outlets.

Featured Local Company

Infinity Network Solutions

478-475-9500
93 Gateway Drive
Macon, GA
www.infinitynetworks.net

Regional Articles
- Should IT Security Be Outsourced? Acworth GA
- Should IT Security Be Outsourced? Albany GA
- Should IT Security Be Outsourced? Alpharetta GA
- Should IT Security Be Outsourced? Americus GA
- Should IT Security Be Outsourced? Athens GA
- Should IT Security Be Outsourced? Atlanta GA
- Should IT Security Be Outsourced? Augusta GA
- Should IT Security Be Outsourced? Austell GA
- Should IT Security Be Outsourced? Baxley GA
- Should IT Security Be Outsourced? Blairsville GA
- Should IT Security Be Outsourced? Brunswick GA
- Should IT Security Be Outsourced? Buford GA
- Should IT Security Be Outsourced? Calhoun GA
- Should IT Security Be Outsourced? Canton GA
- Should IT Security Be Outsourced? Carrollton GA
- Should IT Security Be Outsourced? Cartersville GA
- Should IT Security Be Outsourced? Cedartown GA
- Should IT Security Be Outsourced? Chatsworth GA
- Should IT Security Be Outsourced? Columbus GA
- Should IT Security Be Outsourced? Conyers GA
- Should IT Security Be Outsourced? Cordele GA
- Should IT Security Be Outsourced? Covington GA
- Should IT Security Be Outsourced? Cumming GA
- Should IT Security Be Outsourced? Dacula GA
- Should IT Security Be Outsourced? Dahlonega GA
- Should IT Security Be Outsourced? Dallas GA
- Should IT Security Be Outsourced? Dalton GA
- Should IT Security Be Outsourced? Dawsonville GA
- Should IT Security Be Outsourced? Decatur GA
- Should IT Security Be Outsourced? Douglas GA
- Should IT Security Be Outsourced? Douglasville GA
- Should IT Security Be Outsourced? Dublin GA
- Should IT Security Be Outsourced? Duluth GA
- Should IT Security Be Outsourced? Eatonton GA
- Should IT Security Be Outsourced? Elberton GA
- Should IT Security Be Outsourced? Ellenwood GA
- Should IT Security Be Outsourced? Ellijay GA
- Should IT Security Be Outsourced? Evans GA
- Should IT Security Be Outsourced? Fairburn GA
- Should IT Security Be Outsourced? Fayetteville GA
- Should IT Security Be Outsourced? Fitzgerald GA
- Should IT Security Be Outsourced? Flowery Branch GA
- Should IT Security Be Outsourced? Forest Park GA
- Should IT Security Be Outsourced? Fort Benning GA
- Should IT Security Be Outsourced? Fort Valley GA
- Should IT Security Be Outsourced? Gainesville GA
- Should IT Security Be Outsourced? Griffin GA
- Should IT Security Be Outsourced? Grovetown GA
- Should IT Security Be Outsourced? Hartwell GA
- Should IT Security Be Outsourced? Hephzibah GA
- Should IT Security Be Outsourced? Hinesville GA
- Should IT Security Be Outsourced? Jesup GA
- Should IT Security Be Outsourced? Jonesboro GA
- Should IT Security Be Outsourced? Kennesaw GA
- Should IT Security Be Outsourced? Kingsland GA
- Should IT Security Be Outsourced? La Fayette GA
- Should IT Security Be Outsourced? Lagrange GA
- Should IT Security Be Outsourced? Lawrenceville GA
- Should IT Security Be Outsourced? Lilburn GA
- Should IT Security Be Outsourced? Lithia Springs GA
- Should IT Security Be Outsourced? Lithonia GA
- Should IT Security Be Outsourced? Loganville GA
- Should IT Security Be Outsourced? Mableton GA
- Should IT Security Be Outsourced? Macon GA
- Should IT Security Be Outsourced? Marietta GA
- Should IT Security Be Outsourced? Mcdonough GA
- Should IT Security Be Outsourced? Milledgeville GA
- Should IT Security Be Outsourced? Monroe GA
- Should IT Security Be Outsourced? Morrow GA
- Should IT Security Be Outsourced? Moultrie GA
- Should IT Security Be Outsourced? Newnan GA
- Should IT Security Be Outsourced? Norcross GA
- Should IT Security Be Outsourced? Peachtree City GA
- Should IT Security Be Outsourced? Powder Springs GA
- Should IT Security Be Outsourced? Ringgold GA
- Should IT Security Be Outsourced? Riverdale GA
- Should IT Security Be Outsourced? Rockmart GA
- Should IT Security Be Outsourced? Rome GA
- Should IT Security Be Outsourced? Rossville GA
- Should IT Security Be Outsourced? Roswell GA
- Should IT Security Be Outsourced? Saint Simons Island GA
- Should IT Security Be Outsourced? Savannah GA
- Should IT Security Be Outsourced? Sharpsburg GA
- Should IT Security Be Outsourced? Smyrna GA
- Should IT Security Be Outsourced? Snellville GA
- Should IT Security Be Outsourced? Statesboro GA
- Should IT Security Be Outsourced? Stockbridge GA
- Should IT Security Be Outsourced? Stone Mountain GA
- Should IT Security Be Outsourced? Suwanee GA
- Should IT Security Be Outsourced? Thomaston GA
- Should IT Security Be Outsourced? Thomasville GA
- Should IT Security Be Outsourced? Thomson GA
- Should IT Security Be Outsourced? Tifton GA
- Should IT Security Be Outsourced? Toccoa GA
- Should IT Security Be Outsourced? Tucker GA
- Should IT Security Be Outsourced? Valdosta GA
- Should IT Security Be Outsourced? Vidalia GA
- Should IT Security Be Outsourced? Villa Rica GA
- Should IT Security Be Outsourced? Warner Robins GA
- Should IT Security Be Outsourced? Waycross GA
- Should IT Security Be Outsourced? Winder GA
- Should IT Security Be Outsourced? Woodstock GA
Related Articles
- How to Test for Internet Security Georgia
For businesses, network security and wireless security are crucial because without security in place, when they transfer or access information within the network, others may be able to intercept and view it. Internet security can be tested and validated through the following: Check your anti-virus software. Your test here is as easy as knowing if you have anti-virus software, because if you do, it means your Internet security is one step safer.
- Steps to Safer Virtual Servers Georgia
- Instant Messaging Safety and Security Georgia
- Benchmarking the Outsourcers Georgia
- IT Security Information Georgia
- McAfee Wireless Home Network Security Georgia
- Does Your Security Suite Also Protect Your Privacy? Georgia
- Lower Costs and Reduce Risks by Protecting Endpoints Georgia
- Web Application Security Georgia
- Online Security Setup Georgia
Related Local Events
The Special Event
Dates: 1/13/2010 - 1/15/2010
Location: Georgia World Congress Center, Atlanta
Atlanta, GA
View Details

2009 Annual Conference: Magnify Your Security
Dates: 11/11/2009 - 11/11/2009
Location: Loudermilk Center
Atlanta, GA
View Details

Elcom Caucasus
Dates: 10/29/2009 - 10/31/2009
Location: Georgia World Congress Center
Atlanta, GA
View Details

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History