The Cyber Security Review | Monday, February 07, 2022
Nobody was spared by the pandemic, which caused widespread disruption. However, adversity can bring opportunity, and many of the businesses that prospered as a result of COVID-19 were able to provide customers with something that the crisis took away.
FREMONT, CA: COVID-19 accelerated digital transformation in the business-to-business sector, including cloud, IoT, and other emerging technologies. However, it increased the attack surface and exposed vulnerabilities in organizations now forced to accommodate a distributed workforce via unmanaged technologies. This exacerbated a number of the critical challenges that security teams were already facing, even before their networks grew overnight: an overload of alerts, the need for additional detection tools, and security skill shortages, to name a few.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
During these challenging times, managed security service providers (MSSPs) and managed detection and response (MDR) vendors have emerged as key winners. Additionally, these outsourcing arrangements enable organizations to acquire the internal knowledge they initially lacked, which prompted them to seek assistance from a provider to help fill the gaps in the first place.
In a competitive MSSP market, one way to shed an occasionally shady reputation and differentiate oneself from competitors is to optimize the security operations and deliver maximum value to customers. To accomplish this, providers must overcome some critical contemporary obstacles:
Increasing the cost of customer acquisition: Due to the proliferation of security technology options, customers' security stacks are more diverse than ever before. To compete, MSSPs must be willing and able to support a diverse range of technology, which frequently results in increased acquisition costs and training requirements for security analysts.
Inadequate centralization of visibility: Analyst teams responsible for managing and monitoring a large customer base frequently lack visibility into resource allocation, impairing their ability to balance productivity and risk. Often, this lack of visibility extends to the customer as well. Client’s desire increased visibility into their growing network, increased transparency into what occurs within it, and, most importantly, the ability of an external provider to do more than notify them of a threat. With increasing customers demanding positive outcomes, suppliers must identify, disrupt, and eliminate adversaries and aid organizations that have been harmed to return to their normal operations quickly.
Diverse Modes of Delivery: MSSP delivery models are becoming increasingly diverse, and include 24/7 outsourced SOC, managed SIEM, MDR, staff augmentation, and a variety of hybrid models. These disparate models are convergent—a single MSSP may provide multiple models in various configurations, increasing operational costs and complexity.
Adherence to SLA Commitments: MSSP analyst teams that manage multiple systems and interfaces for a diverse set of clients face significant pressure to meet stringent SLA requirements.
Operation Round-the-Clock: MSSPs work around the clock to meet customer demands, requiring multiple shifts and handoffs. Consistency in response is critical, and staff knowledge and capability variability place additional strain on analysts. Consistency in processes and workflow is critical for balancing productivity and risk.
Turnover of Personnel: Personnel shortages and high turnover exacerbate the difficulties inherent in managing a 24-hour operation. Meanwhile, the pressure is exacerbated further by the reliance on manual processes and retaining expert knowledge.
More in News