Securing A Mid-Sized Enterprise Online

Securing A Mid-Sized Enterprise

There is no longer any subjectivity in this statement: security is at the top of list for all CIOs. Every meeting I’ve attended over the last three months has been dominated by the topic of security and when it’s injected into the conversation, it’s not necessarily by my team, but the customer.

Security has been a hot topic for the last three years beginning when prime time news displayed the list of Fortune 500 logos that had fallen victim to foreign hackers. As with most IT trends, the mid-sized enterprises have followed their larger counterpart’s actions driving their current interest in and need for heightened security. Though this need has been met with confusion, questions and sighs on how to achieve the goal of increasing security and thereby adherence to compliance.

Why the confusion?

security-confusion

Security is a combination of education with the usual people, process and technology equation. For the medium size enterprise this can be a tough equation to solve given limited resources and budget. With the demand for security engineers increasing by 74% over the last three years and 30%-40% of security projects ending up in failed implementations, demonstrating no value to the enterprise, it is easy to see why. So, how do security managers succeed with the odds seemingly stacked against them?

Closing The Security Gap

There are two forces crossing in the industry, which if leveraged appropriately, can help enterprises close their security gap. First, from a technology perspective we are at a point where products have matured to the point where consolidation is possible without the loss of protection. The features of many point products which have emerged over the last three years are now being rolled in as features on existing products such as firewalls or other perimeter security products. By leveraging the mature vendors that offer various security products on a single platform administration effort is lowered while integration and security intelligence is heightened.

One example of this is the concept of “sand boxing” web traffic or email traffic and watching to see if malicious activity occurs. If so, the traffic could be sanitized or blocked.

Sandboxing-Cyber-Attack

(Infographic Source: Fortinet.com)

When this technology first arrived it was introduced by market disruptors and a was a new platform to be absorbed by the security staff. Today, the same feature is now part of many firewalls and web security gateway products that are already in place. A feature to be turned on rather than a new platform to be learned. So the point to take away is look to simplify the management while gaining better integration and security intelligence by consolidating security features on a common product platform.

Managed Service Providers

The second force, driven by Cloud services, is the many Cloud Enabled Managed Service Providers now offering managed security services. These providers can offer managed firewall, IPS, SIEM, web security and email security solution reducing the number of security engineers required to be staffed by the enterprise which solves the staffing shortage for them. In addition to offering the technology to provide these services, the main advantage gained with MSPs is solid process and methodology which assures these tools will provide business value and be successfully implemented.

Virtual Security Officer

Another offering proven to be useful is the VCISO or Virtual Security Officer. Enterprise of medium size often cannot afford a dedicated CISO but still have the need for the position. By contracting with a provider that offers a VCISO, an enterprise can gain access to a CISO skillset for a fraction of the cost of hiring one.

In closing, budget constraints and staffing issues are real barriers and have stopped many companies from achieving their security goals.

Seize the moment, assess your current security environment and look for ways to consolidate and simplify security platforms to gain the most value. Then look to fill the gaps with technology, people and process with qualified Service Providers. Pay special attention to those providers that bring the process and methodology to assure success in the technologies they represent as that is as important as the technology itself. Filling your CISO role with an on demand VCISO can address your CISO needs in an economical and efficient manner.

Marc Malizia

Twitbook.png
The Sticky Note.png
Growing Up.png
Holiday Photos.png
Joseph Carson
Compromised Identities Most of what we encounter every day is computerized. We connect to the internet on our phone or make a purchase with an internet-connected processor, leaving us at risk of a malicious hacker ...
Ronald van Loon
Former head of U.S. Cybersecurity, Chris Krebs, recently cautioned that digital experts are fighting a “pandemic of a different variety” as ransomware attacks across the country increase. Ransomware attacks were up 150% in 2020 versus ...
Bi Tools
BI Tools For Data Scientists Many data scientists prefer to use open-source framework to code scripts; after all, it’s something they already trust to work. Business intelligence tools like Qlik Sense, Power BI, or Tableau, ...
Gilad David Maayan
Cloud Security Posture Management Cloud Security Posture Management (CSPM) enables you to secure cloud data and resources. You can integrate CSPM into your development process, to ensure continuous visibility. CSPM is particularly beneficial for DevOps ...
Derrek Schutman
Implementing Digital Capabilities Successfully Building robust digital capabilities can deliver huge benefits to Digital Service Providers (DSPs). A recent TMForum survey shows that building digital capabilities (including digitization of customer experience and operations), is the ...