But handling the ongoing relationship after you've chosen the provider might be even more important, experts say.
Most enterprises these days are hiring a single managed security service provider, not multiple providers, experts say. This means you'd better be sure you find one you can work with over the long haul.
"As a company that wades into this, you have to look at the longer-term vision," says Mike Mulville, CTO at SAIC, which offers security and professional services. "You have to look further down the road and ask if the vendors have the capability to do what you need to do."
With the tough economy, some companies have slimmed down their IT security departments, and many are looking to find a managed security service to fill the gaps. Cost has been a chief reason for outsourcing in the past, as well as expertise and 24x7 support.
"People are coming to us because they don't have the expertise to deal with threats," says Joe Blanda, executive director at AT&T managed security services. "The complexity is at the point that people don't want to have to deal with it."
Such demands have boosted the managed security services market to skyrocketing growth -- the market is projected to increase from $1.2 billion in 2009 to $3.9 billion in 2016, according to research firm Frost & Sullivan.
But while the need for a variety of services is growing, most enterprises would rather use one provider, experts say. "Using one vendor that can help with all these headaches seems to be appealing to the customers," says Martha Vazquez, a research analyst for Frost & Sullivan.
Once you decide on a provider, it's equally important to manage the relationship carefully, observers say. For example, make sure you are meeting regularly -- at least monthly -- with your provider, SAIC's Mulville says. Rather than review performance every few years when it's time to sign a new contract, companies should check in regularly. Good providers will meet often with clients to discuss ongoing performance and any significant security incidents, he says.
"Over time, the [service providers'] ability to show value has gotten better," Mulville says. "[Meeting with clients] is a greater opportunity to do that, so you don't have to wait for contract time."
Rewarding providers for finding and reporting evidence of security events can result in better security, according to a recent report.
In a 2008 report, research firm Aberdeen classified security services users into three categories -- best-in-class, average, and laggards -- based on metrics measuring their security. Almost three-quarters of best-in-class firms had good communications with their providers, compared to 56 percent of laggards. Six out of 10 companies in the top class had a specific person or committee assigned to evaluating the suitability of managed security service providers, compared to 44 percent for laggards.
Such centralized management can help companies communicate new needs to their providers, Vazquez says. Customers should also look for providers that allow mixing and matching of services, she says.
"Offering a mix of services and flexibility will allow the customer to utilize different price points and packages tailored for their needs," Vazquez says. "I believe just finding an MSSP that will stay ahead of the trends through innovation and offering various new services will help the customer maximize its benefits."
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Using Service Providers To Manage DDoS Threats
When it comes to the battle against distributed denial-of-service attacks, you are not alone. With the increasing use of third-party service providers, your organization likely has a huge arsenal of bandwidth, technology and know-how at its disposal. The challenge is to effectively marshal those resources among your providers and integrate them with your own security measures into a strategic and comprehensive DDoS protection plan.
Hosted Web Security Services: Block Malware Before Your Border
Security service providers are now delivering a wide range of packaged offerings, including Web content filtering, anti-malware, data leak prevention, and many other capabilities. How can your organization take advantage of these Web security services, and how can you choose the right provider? This Dark Reading Tech Center report offers a look at these services and some recommendations on how best to implement them.
You've Got (Secure) Mail: Using Service Providers to Boost Protection
The SaaS market is still in its infancy, but hosted e-mail security firms are leading the way, thanks to ease of implementation and many obvious benefits. Still, these services are not without risks. In this Dark Reading Tech Center report, we'll discuss how to determine what mix of in-house and hosted email security makes sense for your organization.
Other reports from the Security Services Tech Center:
| Sponsored by: |
Establishing a Formal Cyber Intelligence Capability
Organizations are realizing that advanced intelligence capabilities consistently deliver substantial cost savings - with proactive insights on true threats, the intelligence to avoid false alarms, and the system and application availability required to preserve revenues and customer loyalty. But achieving these benefits requires organizations to establish a formal cyber intelligence capability. Read this whitepaper to learn about a proven, repeatable process with clearly established steps for setting up an in-house cyber security intelligence operation.
DDoS Mitigation: Best Practices for a Rapidly Changing Threat Landscape
Although DDoS attacks have become a mainstay of hackers' arsenals, their profile has changed considerably in the past year, making them an even greater threat to companies that conduct business online. DDoS attacks are larger, stealthier, more targeted, and more sophisticated than ever. Get best practices to enable your organization to keep pace with DDoS attacks while minimizing impact on business operations.
2012 Cyber Crime Threats and Trends
Get the highlights of 2011 cyber security trends and how those trends and others might unfold in 2012. This report is a strategic complement to daily tactical intelligence reports and provides IT security and business operations with actionable and relevant decision support.
Using Hybrid Routing to Optimize DNS Resolution Performance and Reliability
To create a satisfactory end user experience, enterprises must ensure that DNS resolution is fast and reliable. Learn more about how using a hybrid routing solution can greatly maximize performance while minimizing latency-and address your business' specific needs along the way.
A Cost Analysis of Approaches To DDoS Protection.
All organizations with an online presence or dependence on Internet-based systems need to fortify their defenses against DDoS attacks. DDoS can cost an organization in tangible losses and in more subtle ways. Read this whitepaper for a deeper perspective on the cost benefits of a dedicated, cloud-based DDoS service over an in-house hardware solution or over-provisioning through your ISP.
MORE NEWSFEED >>>