Should IT Security Be Outsourced? Michigan

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

Local Companies

oakood hospital
313 337 0450
1r462 linden st
dearborn, MI
Aspiryon
866-353-8184
24275 NW HWY
Southfield, MI
Mulhern Hastings & Assoc
(313) 964-4190
407 E Fort St
Detroit, MI
A.R.A.B. Investments
(313) 359-6969
1548 N John Daly Rd
Dearborn Heights, MI
Improvement Path Systems
(248) 477-7447
24843 Ivywood Dr
Farmington Hills, MI
Cleveland Consulting Inc
(517) 655-2625
Williamston, MI
Southfield Oxford Associates Llc
(248) 356-5488
26300 Northwestern Hwy
Southfield, MI
Reserve International
(313) 849-2857
8501 W Fort St
Detroit, MI
Citizens Bank
(810) 766-7644
154 W Main St
Otisville, MI
Eenterprise
(616) 896-0283
3111 N Wilson Ct NW
Grand Rapids, MI



By Renee Oricchio

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

"Always retain what is required to protect the brand," says Paul Roehrig, a principal analyst from Forrester Research, who says outsourcing security can be appropriate, but proceed with caution.

Look no further than the story of TJX, the national retailer that owns such chains as T.J. Maxx, HomeGoods, Marshalls and Bob's Stores. In January of 2007, TJX had to publicly admit the most sensitive part of its network had been hacked, exposing the numbers of more than 45 million customer debit and credit cards. In the wake of what is considered to be the worst breach of consumer data ever, dozens of banks were forced to cancel and reissue millions of cards, while TJX faced countless lawsuits and relentless bad press.

"TJX is the poster child that illustrates the bigger they are, the harder they fall," says Ben Rothke, a senior security consultant for the security firm BT INS.

While some IT managers may see TJX as a cautionary tale to keep something as important as network security in-house, Rothke believes the TJX story actually makes a compelling case to do the very opposite.

"When hackers stole customer data from TJX, what made matters worse is that it went on for so long undetected, and once identified, they were slow to tell clients," says Rothke. He adds that most IT departments are notoriously understaffed and underbudgeted when it comes to security.

Here are some of the security functions that could be outsourced in large organizations:

  • Intrusion detection Intrusion detection (IDS) "takes a certain set of protocols and expertise to understand. For most IT departments it's not a core competency," says Rothke. For CIOs who don't already have IDS technology deployed, it can't be done overnight either. The right IDS vendor will already have an infrastructure in place, making rapid implementation possible.
  • Firewall security This, too, is its own discipline, troubleshooting the efficacy of the network firewall or firewalls. What's the firewall protecting? Where are the holes? And how are they to be plugged? Companies need a vendor that understands the nature of rule changes, documents those changes as they happen, and offers 24/7 support.
  • Incident response While intrusion detection is all about discovering a breach when it happens, incident response is all about having the right protocols in place to react. Again, looking back at the TJX case, two of the biggest mistakes the company made that magnified the disaster were the inability to realize there had been a breach going on for months undetected, as well as their slow reaction alerting customers and the public in the aftermath.
  • Forensics How did the breach happen? The kind of security expert that keeps vigil over the network is not necessarily the same person to play detective once the damage has been done. To date, no one has definitively figured out how the TJX breach happened or who was directly responsible. The company suspects wireless transmissions used out of two Miami stores were hacked. With an outside forensics expert, there is the added benefit of third-party objectivity and no self-interest to cover up findings, experts say.
  • Vulnerability scanning The other kind of security expert needed to protect the network is one who can audit and aggregate the risks in all of the above areas and implement routine testing.

While these are the most popular areas of expertise to outsource, Roehrig draws the line between what should stay in-house and what can go out of house more simply.

"Outsourcing can be a great solution for implementation and support, but architecture and setting security policies should stay within the firm," he says.

Outsourcing security: the rules of the road
"If done right, the benefits of outsourcing security are compelling. If done wrong, the risks can be significant," says Rothke.

Here are some strategies to make outsourcing work:

  • Find a good match There are consulting groups that can offer a team of experts to cover all those specific areas of concern: intrusion detection, firewall security, incident response, forensics and vulnerability scanning. CIOs would be wise to assess in advance which of those areas need outside expertise and whether it's better to have one vendor handling everything, or instead compartmentalizing certain areas with multiple vendors.
  • Appoint an in-house liaison to manage the relationship Vendor management by an insider is key. At least one person from the IT department needs to monitor the relationship explaining the needs of the business and its culture to the security consultant.
  • Don't be cheap The right person or firm is not likely to be the most affordable solution. Rothke warns there are plenty of "Mom and Pop" security firms out there. The good ones are a rare commodity and charge accordingly. Plan on paying for quality.

However a CIO decides to handle network security, Rothke offers this final piece of advice: "Hardware's cheap, bandwidth is cheap, contractors in India are cheap. But lawyers are expensive."

Renee Oricchio is a freelance writer in Norwalk, Conn. For the past 20 years, she has been writing and producing news segments about technology and business for CNN, MSNBC, Ziff-Davis, CNET and a variety of Silicon Valley-based local news outlets.

Featured Local Company

oakood hospital

313 337 0450
1r462 linden st
dearborn, MI

Regional Articles
- Should IT Security Be Outsourced? Adrian MI
- Should IT Security Be Outsourced? Allegan MI
- Should IT Security Be Outsourced? Allen Park MI
- Should IT Security Be Outsourced? Alpena MI
- Should IT Security Be Outsourced? Ann Arbor MI
- Should IT Security Be Outsourced? Auburn Hills MI
- Should IT Security Be Outsourced? Battle Creek MI
- Should IT Security Be Outsourced? Bay City MI
- Should IT Security Be Outsourced? Belleville MI
- Should IT Security Be Outsourced? Benton Harbor MI
- Should IT Security Be Outsourced? Berkley MI
- Should IT Security Be Outsourced? Big Rapids MI
- Should IT Security Be Outsourced? Bloomfield Hills MI
- Should IT Security Be Outsourced? Brighton MI
- Should IT Security Be Outsourced? Burton MI
- Should IT Security Be Outsourced? Cadillac MI
- Should IT Security Be Outsourced? Canton MI
- Should IT Security Be Outsourced? Cheboygan MI
- Should IT Security Be Outsourced? Clarkston MI
- Should IT Security Be Outsourced? Clinton Township MI
- Should IT Security Be Outsourced? Clio MI
- Should IT Security Be Outsourced? Coldwater MI
- Should IT Security Be Outsourced? Commerce Township MI
- Should IT Security Be Outsourced? Comstock Park MI
- Should IT Security Be Outsourced? Davison MI
- Should IT Security Be Outsourced? Dearborn Heights MI
- Should IT Security Be Outsourced? Dearborn MI
- Should IT Security Be Outsourced? Detroit MI
- Should IT Security Be Outsourced? Dowagiac MI
- Should IT Security Be Outsourced? East Lansing MI
- Should IT Security Be Outsourced? Eastpointe MI
- Should IT Security Be Outsourced? Eaton Rapids MI
- Should IT Security Be Outsourced? Escanaba MI
- Should IT Security Be Outsourced? Farmington MI
- Should IT Security Be Outsourced? Fenton MI
- Should IT Security Be Outsourced? Ferndale MI
- Should IT Security Be Outsourced? Flat Rock MI
- Should IT Security Be Outsourced? Flint MI
- Should IT Security Be Outsourced? Flushing MI
- Should IT Security Be Outsourced? Fort Gratiot MI
- Should IT Security Be Outsourced? Fraser MI
- Should IT Security Be Outsourced? Garden City MI
- Should IT Security Be Outsourced? Gaylord MI
- Should IT Security Be Outsourced? Gladwin MI
- Should IT Security Be Outsourced? Grand Blanc MI
- Should IT Security Be Outsourced? Grand Haven MI
- Should IT Security Be Outsourced? Grand Ledge MI
- Should IT Security Be Outsourced? Grand Rapids MI
- Should IT Security Be Outsourced? Grandville MI
- Should IT Security Be Outsourced? Grosse Pointe MI
- Should IT Security Be Outsourced? Hamtramck MI
- Should IT Security Be Outsourced? Harper Woods MI
- Should IT Security Be Outsourced? Harrison Township MI
- Should IT Security Be Outsourced? Hazel Park MI
- Should IT Security Be Outsourced? Highland Park MI
- Should IT Security Be Outsourced? Hillsdale MI
- Should IT Security Be Outsourced? Holland MI
- Should IT Security Be Outsourced? Holly MI
- Should IT Security Be Outsourced? Holt MI
- Should IT Security Be Outsourced? Howell MI
- Should IT Security Be Outsourced? Hudsonville MI
- Should IT Security Be Outsourced? Inkster MI
- Should IT Security Be Outsourced? Ionia MI
- Should IT Security Be Outsourced? Jackson MI
- Should IT Security Be Outsourced? Jenison MI
- Should IT Security Be Outsourced? Kalamazoo MI
- Should IT Security Be Outsourced? Lake Orion MI
- Should IT Security Be Outsourced? Lansing MI
- Should IT Security Be Outsourced? Lapeer MI
- Should IT Security Be Outsourced? Lincoln Park MI
- Should IT Security Be Outsourced? Livonia MI
- Should IT Security Be Outsourced? Ludington MI
- Should IT Security Be Outsourced? Macomb MI
- Should IT Security Be Outsourced? Marquette MI
- Should IT Security Be Outsourced? Midland MI
- Should IT Security Be Outsourced? Monroe MI
- Should IT Security Be Outsourced? Mount Clemens MI
- Should IT Security Be Outsourced? Mount Morris MI
- Should IT Security Be Outsourced? Mount Pleasant MI
- Should IT Security Be Outsourced? Muskegon MI
- Should IT Security Be Outsourced? New Baltimore MI
- Should IT Security Be Outsourced? Niles MI
- Should IT Security Be Outsourced? Northville MI
- Should IT Security Be Outsourced? Novi MI
- Should IT Security Be Outsourced? Oak Park MI
- Should IT Security Be Outsourced? Okemos MI
- Should IT Security Be Outsourced? Owosso MI
- Should IT Security Be Outsourced? Petoskey MI
- Should IT Security Be Outsourced? Pinckney MI
- Should IT Security Be Outsourced? Plymouth MI
- Should IT Security Be Outsourced? Pontiac MI
- Should IT Security Be Outsourced? Port Huron MI
- Should IT Security Be Outsourced? Portage MI
- Should IT Security Be Outsourced? Redford MI
- Should IT Security Be Outsourced? Rochester MI
- Should IT Security Be Outsourced? Rockford MI
- Should IT Security Be Outsourced? Romulus MI
- Should IT Security Be Outsourced? Roseville MI
- Should IT Security Be Outsourced? Royal Oak MI
- Should IT Security Be Outsourced? Saginaw MI
- Should IT Security Be Outsourced? Saint Clair Shores MI
- Should IT Security Be Outsourced? Saint Johns MI
- Should IT Security Be Outsourced? Saline MI
- Should IT Security Be Outsourced? Sault Sainte Marie MI
- Should IT Security Be Outsourced? South Haven MI
- Should IT Security Be Outsourced? South Lyon MI
- Should IT Security Be Outsourced? Southfield MI
- Should IT Security Be Outsourced? Southgate MI
- Should IT Security Be Outsourced? Sterling Heights MI
- Should IT Security Be Outsourced? Sturgis MI
- Should IT Security Be Outsourced? Swartz Creek MI
- Should IT Security Be Outsourced? Taylor MI
- Should IT Security Be Outsourced? Temperance MI
- Should IT Security Be Outsourced? Three Rivers MI
- Should IT Security Be Outsourced? Traverse City MI
- Should IT Security Be Outsourced? Trenton MI
- Should IT Security Be Outsourced? Troy MI
- Should IT Security Be Outsourced? Utica MI
- Should IT Security Be Outsourced? Walled Lake MI
- Should IT Security Be Outsourced? Warren MI
- Should IT Security Be Outsourced? Waterford MI
- Should IT Security Be Outsourced? West Bloomfield MI
- Should IT Security Be Outsourced? Westland MI
- Should IT Security Be Outsourced? White Lake MI
- Should IT Security Be Outsourced? Wixom MI
- Should IT Security Be Outsourced? Wyandotte MI
- Should IT Security Be Outsourced? Wyoming MI
- Should IT Security Be Outsourced? Ypsilanti MI
- Should IT Security Be Outsourced? Zeeland MI
Related Articles
- Online Security Setup Michigan
There isn't a great deal to smile about with the security setup for Co-op's online-only bank. Login requires you to enter your sort code and account number - two details that are easily lifted from your bank card. You also have to provide the answer to one of several "personal questions", such as the name of the schools you attended, and your mother's maiden name - all easy fodder for ID thieves on social-networking sites.
- Benchmarking the Outsourcers Michigan
- Steps to Safer Virtual Servers Michigan
- McAfee Wireless Home Network Security Michigan
- How to Test for Internet Security Michigan
- Instant Messaging Safety and Security Michigan
- Web Application Security Michigan
- IT Security Information Michigan
- Does Your Security Suite Also Protect Your Privacy? Michigan
- Lower Costs and Reduce Risks by Protecting Endpoints Michigan

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History