ICBC Standard Bank

The Case for Managed Security Service Providers (MSSP)

The current headlines about cyber-attacks as part of the hybrid warfare between Russia and Ukraine, and the recent major attacks in the “virtual world” leading to impact on the “real world” such as the Colonial Pipeline ransomware attack has raised the importance of Cyber Security in our day to day lives in addition to being a critical area of focus for most Enterprises.

HOW MUCH SHOULD AN ENTERPRISE SPEND ON CYBER SECURITY

While there are various surveys which provide differing views on how much should an organisation spend vs how much they actually spend on Cyber Security services, there is no right answer and it varies from organisation to organisation.

My own experience of Enterprises’ allocation of Cyber Security budget as a percentage of IT budgetsaligns to a survey by a global Market Intelligence firm, IDC, which spells out the following results:

A more recent 2020 survey from a leading European Cyber Security firm, Kaspersky, estimated the Cyber Security spend, as a percentage of total IT budget, for Small and Medium Business increased from 23% (in 2019) to 26% (in 2020); and in case of Enterprises from and 26% (2019) to 29% (2020).

While Enterprises are forced to invest in the improving their Cyber Security posture, the reality is most don’t have adequate investment, capacity or capability to defend themselves against external sophisticated targeted attacks by nation states, intelligence agencies or from internal malicious insiders. Protection against such attacks require significant investment to build in-house capabilities which is not always feasible. Also, many organisations have a false sense of security, and will not invest in security till they actually suffer a major cyber incident, which in some cases, may be too late.

THE CASE FOR MSSPS

Leveraging Managed Security Service Providers, orMSSPs,provides a great way of getting access to enhanced cyber security protection capability and capacity at an affordable price point.

One small-size Investment Bank that I worked forduring my Management Consulting days, had just five Cyber Security focused internal staff (approx. 1/5th compared to its peers) which provided end to end of security across the bankwhile leveraging services from multiple MSSPs. While this level of staffing was clearly inadequate for an organisation its size and complexity, the Bank managed to manage the “head count” challenge and still have an “effective” securitythrough smarter leverage of MSSPs and cloud services to maximise the security for an approx. investment of approx.15% of the total IT spend.

This organisation spent close to 30% of its total IT Security budget on services from MSSP and less than 20% on staff costs.

See below for a representative view of the IT security spend and split.

HOW MSSPS CAN ADD VALUE

MSSPs are known to provide a mix of security monitoring services; advisory and consulting services; assurance services such as audits and compliance assessment; and product resale.

Following are examples of common services available through MSSPs:

• Security Information and Event Management (SIEM) alert monitoring and response

• Firewall rules management and monitoring

• Intrusion Prevention Detection and Response

• Red Team and Penetration testing

• Vulnerability Management

• Incident Response Retainer

• Actionable Threat Intelligence and brand monitoring

The following table provides my views on the advantages or using MSSPs along with the Critical Success Factors to make this work effectively.

CHOOSING THE RIGHT MSSP

Organisational needs are typically different and so are the criteria for selection. A MSSP may rarely offers complete customisation of the services on offer as they are shared among multiple customers. Evaluating a managed security service provider can be difficult because not every service offered by an MSSP provides value to a company. Determining the right MSSP for an environment requires examining which area of evaluation to determine which is most important for anEnterprise.

Cost should not be the only factor when considering security services. Depending on the nature of anEnterprise, certain MSSPs also offer services to assist Enterprises in regulated industries.

Top considerations while choosing a MSSP should be:

• Round the clock services

• Real Time Response and proactive services; check SLAs that the MSSP is ready to commit

• High Availability

• Budget

• Integration with other security and Infrastructure tools and processes within your organisation

RECENT TRENDS

The services provided by MSSPs is reaching a saturation point with multiple previously low-cost offshore service providers entering this field and pushing the profitability margins for traditional players.

To use advanced threat detection capabilities, a growing number of organisations are now choosing to work with Managed Detection and Response (MDR) providers instead of MSSPs.

Unlike MSSPs, MDR services are specialists, commonly turnkey, threat intelligence and detection technologies as part of one comprehensive service offering.

Whether MDR from being the latest “buzz word” to being a complete replacement of MSSPs is to be seen. We can already see a number of MSSPs re-packing and re-introducing their services as MDR.

ABOUT PRAVEEN SINGH

Praveen leads IT Risk and Cyber Security for ICBC Standard Bank. Prior to joining the Bank, Praveen worked as a management consultant for Big4 consulting firms. He has 20+ years of FS sector experience in IT delivery, CIO advisory, Transformation, Outsourcing, Risk and Regulation across UK, US, India and China.Away from work, he likes to speak at industry events on matters of Technology and Security and supports local charities. He also likes to spend time with his 11-year-old daughter and is a big fan of Formula 1 and cricket.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.