Should IT Security Be Outsourced? Ohio

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

Local Companies

NovaCoast Inc.
(513) 583-8625
600 West Loveland Avenue
Loveland, OH
Advanced Computer Graphics Inc.
(513) 936-5060
10895 Indeco Drive
Cincinnati, OH
NextStep Networking Inc.
(513) 792-3400
10865 Indeco Drive
Cincinnati, OH
Data Processing Sciences Corp.
(513) 791-7100
10810 Kenwood Road
Cincinnati, OH
Solutions Guided Technologies, Inc.
(513) 753-3323
33 East Main Street
Amelia, OH
SCS Technologies
(513) 563-6400
337 West Benson Street
Reading, OH
Zipscene
(513) 477-9090
2118 Saint James Avenue
Cincinnati, OH
Connective Computing Inc.
(513) 475-5660
2200 Victory Parkway
Cincinnati, OH
Apachi Networks
(513) 939-1111
4710 J Interstate Drive
Cincinnati, OH
D L P Technologies Inc.
(513) 232-7791
8080 Reading Road
Cincinnati, OH

 



By Renee Oricchio

For many CIOs, outsourcing security may sound like handing over the keys to the kingdom. It's easy to imagine why some would never even consider outsourcing, knowing that if something does go wrong, it won't be the security vendor left holding the bag. When there's a security breach, it's the corporate brand itself that's in peril.

"Always retain what is required to protect the brand," says Paul Roehrig, a principal analyst from Forrester Research, who says outsourcing security can be appropriate, but proceed with caution.

Look no further than the story of TJX, the national retailer that owns such chains as T.J. Maxx, HomeGoods, Marshalls and Bob's Stores. In January of 2007, TJX had to publicly admit the most sensitive part of its network had been hacked, exposing the numbers of more than 45 million customer debit and credit cards. In the wake of what is considered to be the worst breach of consumer data ever, dozens of banks were forced to cancel and reissue millions of cards, while TJX faced countless lawsuits and relentless bad press.

"TJX is the poster child that illustrates the bigger they are, the harder they fall," says Ben Rothke, a senior security consultant for the security firm BT INS.

While some IT managers may see TJX as a cautionary tale to keep something as important as network security in-house, Rothke believes the TJX story actually makes a compelling case to do the very opposite.

"When hackers stole customer data from TJX, what made matters worse is that it went on for so long undetected, and once identified, they were slow to tell clients," says Rothke. He adds that most IT departments are notoriously understaffed and underbudgeted when it comes to security.

Here are some of the security functions that could be outsourced in large organizations:

  • Intrusion detection Intrusion detection (IDS) "takes a certain set of protocols and expertise to understand. For most IT departments it's not a core competency," says Rothke. For CIOs who don't already have IDS technology deployed, it can't be done overnight either. The right IDS vendor will already have an infrastructure in place, making rapid implementation possible.
  • Firewall security This, too, is its own discipline, troubleshooting the efficacy of the network firewall or firewalls. What's the firewall protecting? Where are the holes? And how are they to be plugged? Companies need a vendor that understands the nature of rule changes, documents those changes as they happen, and offers 24/7 support.
  • Incident response While intrusion detection is all about discovering a breach when it happens, incident response is all about having the right protocols in place to react. Again, looking back at the TJX case, two of the biggest mistakes the company made that magnified the disaster were the inability to realize there had been a breach going on for months undetected, as well as their slow reaction alerting customers and the public in the aftermath.
  • Forensics How did the breach happen? The kind of security expert that keeps vigil over the network is not necessarily the same person to play detective once the damage has been done. To date, no one has definitively figured out how the TJX breach happened or who was directly responsible. The company suspects wireless transmissions used out of two Miami stores were hacked. With an outside forensics expert, there is the added benefit of third-party objectivity and no self-interest to cover up findings, experts say.
  • Vulnerability scanning The other kind of security expert needed to protect the network is one who can audit and aggregate the risks in all of the above areas and implement routine testing.

While these are the most popular areas of expertise to outsource, Roehrig draws the line between what should stay in-house and what can go out of house more simply.

"Outsourcing can be a great solution for implementation and support, but architecture and setting security policies should stay within the firm," he says.

Outsourcing security: the rules of the road
"If done right, the benefits of outsourcing security are compelling. If done wrong, the risks can be significant," says Rothke.

Here are some strategies to make outsourcing work:

  • Find a good match There are consulting groups that can offer a team of experts to cover all those specific areas of concern: intrusion detection, firewall security, incident response, forensics and vulnerability scanning. CIOs would be wise to assess in advance which of those areas need outside expertise and whether it's better to have one vendor handling everything, or instead compartmentalizing certain areas with multiple vendors.
  • Appoint an in-house liaison to manage the relationship Vendor management by an insider is key. At least one person from the IT department needs to monitor the relationship explaining the needs of the business and its culture to the security consultant.
  • Don't be cheap The right person or firm is not likely to be the most affordable solution. Rothke warns there are plenty of "Mom and Pop" security firms out there. The good ones are a rare commodity and charge accordingly. Plan on paying for quality.

However a CIO decides to handle network security, Rothke offers this final piece of advice: "Hardware's cheap, bandwidth is cheap, contractors in India are cheap. But lawyers are expensive."

Renee Oricchio is a freelance writer in Norwalk, Conn. For the past 20 years, she has been writing and producing news segments about technology and business for CNN, MSNBC, Ziff-Davis, CNET and a variety of Silicon Valley-based local news outlets.

Featured Local Company

NovaCoast Inc.

(513) 583-8625
600 West Loveland Avenue
Loveland, OH

Related Articles
Regional Articles
- Should IT Security Be Outsourced? Akron OH
- Should IT Security Be Outsourced? Alliance OH
- Should IT Security Be Outsourced? Amelia OH
- Should IT Security Be Outsourced? Ashland OH
- Should IT Security Be Outsourced? Ashtabula OH
- Should IT Security Be Outsourced? Athens OH
- Should IT Security Be Outsourced? Avon Lake OH
- Should IT Security Be Outsourced? Barberton OH
- Should IT Security Be Outsourced? Batavia OH
- Should IT Security Be Outsourced? Bay Village OH
- Should IT Security Be Outsourced? Beachwood OH
- Should IT Security Be Outsourced? Bedford OH
- Should IT Security Be Outsourced? Bellefontaine OH
- Should IT Security Be Outsourced? Bowling Green OH
- Should IT Security Be Outsourced? Broadview Heights OH
- Should IT Security Be Outsourced? Brook Park OH
- Should IT Security Be Outsourced? Brunswick OH
- Should IT Security Be Outsourced? Bucyrus OH
- Should IT Security Be Outsourced? Canal Winchester OH
- Should IT Security Be Outsourced? Canfield OH
- Should IT Security Be Outsourced? Canton OH
- Should IT Security Be Outsourced? Celina OH
- Should IT Security Be Outsourced? Chagrin Falls OH
- Should IT Security Be Outsourced? Chardon OH
- Should IT Security Be Outsourced? Chillicothe OH
- Should IT Security Be Outsourced? Cincinnati OH
- Should IT Security Be Outsourced? Circleville OH
- Should IT Security Be Outsourced? Cleveland OH
- Should IT Security Be Outsourced? Columbus OH
- Should IT Security Be Outsourced? Conneaut OH
- Should IT Security Be Outsourced? Coshocton OH
- Should IT Security Be Outsourced? Cuyahoga Falls OH
- Should IT Security Be Outsourced? Dayton OH
- Should IT Security Be Outsourced? Defiance OH
- Should IT Security Be Outsourced? Delaware OH
- Should IT Security Be Outsourced? Dublin OH
- Should IT Security Be Outsourced? East Liverpool OH
- Should IT Security Be Outsourced? Eastlake OH
- Should IT Security Be Outsourced? Eaton OH
- Should IT Security Be Outsourced? Elyria OH
- Should IT Security Be Outsourced? Euclid OH
- Should IT Security Be Outsourced? Fairborn OH
- Should IT Security Be Outsourced? Fairfield OH
- Should IT Security Be Outsourced? Findlay OH
- Should IT Security Be Outsourced? Fostoria OH
- Should IT Security Be Outsourced? Franklin OH
- Should IT Security Be Outsourced? Fremont OH
- Should IT Security Be Outsourced? Galion OH
- Should IT Security Be Outsourced? Gallipolis OH
- Should IT Security Be Outsourced? Galloway OH
- Should IT Security Be Outsourced? Girard OH
- Should IT Security Be Outsourced? Grove City OH
- Should IT Security Be Outsourced? Hamilton OH
- Should IT Security Be Outsourced? Heath OH
- Should IT Security Be Outsourced? Hilliard OH
- Should IT Security Be Outsourced? Hubbard OH
- Should IT Security Be Outsourced? Ironton OH
- Should IT Security Be Outsourced? Kent OH
- Should IT Security Be Outsourced? Lakewood OH
- Should IT Security Be Outsourced? Lancaster OH
- Should IT Security Be Outsourced? Lebanon OH
- Should IT Security Be Outsourced? Lima OH
- Should IT Security Be Outsourced? Lorain OH
- Should IT Security Be Outsourced? Loveland OH
- Should IT Security Be Outsourced? Madison OH
- Should IT Security Be Outsourced? Maineville OH
- Should IT Security Be Outsourced? Mansfield OH
- Should IT Security Be Outsourced? Maple Heights OH
- Should IT Security Be Outsourced? Marion OH
- Should IT Security Be Outsourced? Marysville OH
- Should IT Security Be Outsourced? Mason OH
- Should IT Security Be Outsourced? Massillon OH
- Should IT Security Be Outsourced? Maumee OH
- Should IT Security Be Outsourced? Medina OH
- Should IT Security Be Outsourced? Mentor OH
- Should IT Security Be Outsourced? Miamisburg OH
- Should IT Security Be Outsourced? Middletown OH
- Should IT Security Be Outsourced? Milford OH
- Should IT Security Be Outsourced? Millersburg OH
- Should IT Security Be Outsourced? Mount Vernon OH
- Should IT Security Be Outsourced? Napoleon OH
- Should IT Security Be Outsourced? New Carlisle OH
- Should IT Security Be Outsourced? New Philadelphia OH
- Should IT Security Be Outsourced? Newark OH
- Should IT Security Be Outsourced? North Olmsted OH
- Should IT Security Be Outsourced? North Ridgeville OH
- Should IT Security Be Outsourced? North Royalton OH
- Should IT Security Be Outsourced? Olmsted Falls OH
- Should IT Security Be Outsourced? Oregon OH
- Should IT Security Be Outsourced? Oxford OH
- Should IT Security Be Outsourced? Painesville OH
- Should IT Security Be Outsourced? Pataskala OH
- Should IT Security Be Outsourced? Perrysburg OH
- Should IT Security Be Outsourced? Pickerington OH
- Should IT Security Be Outsourced? Piqua OH
- Should IT Security Be Outsourced? Portsmouth OH
- Should IT Security Be Outsourced? Ravenna OH
- Should IT Security Be Outsourced? Reynoldsburg OH
- Should IT Security Be Outsourced? Rocky River OH
- Should IT Security Be Outsourced? Salem OH
- Should IT Security Be Outsourced? Sandusky OH
- Should IT Security Be Outsourced? Sidney OH
- Should IT Security Be Outsourced? Solon OH
- Should IT Security Be Outsourced? Springboro OH
- Should IT Security Be Outsourced? Springfield OH
- Should IT Security Be Outsourced? Steubenville OH
- Should IT Security Be Outsourced? Stow OH
- Should IT Security Be Outsourced? Strongsville OH
- Should IT Security Be Outsourced? Sylvania OH
- Should IT Security Be Outsourced? Tallmadge OH
- Should IT Security Be Outsourced? Tiffin OH
- Should IT Security Be Outsourced? Tipp City OH
- Should IT Security Be Outsourced? Toledo OH
- Should IT Security Be Outsourced? Troy OH
- Should IT Security Be Outsourced? Twinsburg OH
- Should IT Security Be Outsourced? Van Wert OH
- Should IT Security Be Outsourced? Vandalia OH
- Should IT Security Be Outsourced? Vermilion OH
- Should IT Security Be Outsourced? Wadsworth OH
- Should IT Security Be Outsourced? Wapakoneta OH
- Should IT Security Be Outsourced? Warren OH
- Should IT Security Be Outsourced? Washington Court House OH
- Should IT Security Be Outsourced? West Chester OH
- Should IT Security Be Outsourced? Westerville OH
- Should IT Security Be Outsourced? Westlake OH
- Should IT Security Be Outsourced? Wickliffe OH
- Should IT Security Be Outsourced? Willoughby OH
- Should IT Security Be Outsourced? Wooster OH
- Should IT Security Be Outsourced? Xenia OH
- Should IT Security Be Outsourced? Youngstown OH
- Should IT Security Be Outsourced? Zanesville OH

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History