Welcome Guest. | Log In | Register | Membership Benefits

SaaS Offerings May Play Key Role In Small Business Security, Report Says

As offerings expand, SMBs may get capabilities previously available only to large enterprises, report says

Nov 10, 2009 | 06:42 AM | 

By Randy George

[Excerpted from "Security Services Strategies For Small And Midsize Firms," a new report published today in Dark Reading's Security Services Tech Center.]

Hackers don't care how big your business is.

As a result, many small and midsize businesses today have enterprise-class security vulnerabilities -- and only a fraction of enterprise security budgets. To help close the gap, many SMBs are turning to third-party security services, according to a new report published today by Dark Reading and InformationWeek Analytics.

"Mixing in software-as-a-service options where possible and recovering some man-hours to actually define, manage, and enforce your security plan is becoming an increasingly attractive option" for SMBs, according to "Security Services Strategies For Small And Midsize Firms," a new report available today on Dark Reading.

The report outlines some of the differences between the needs of the small business and those of the large enterprise.

"The biggest thing SMB IT pros have going for them is an intimate knowledge of how the business operates, where its sensitive data resides, and what its weak points are," the report states. "By contrast, big business IT execs have must unwind complex business processes and navigate large organizational structures in order to clearly understand the security landscape. Enterprises' weak points are tough to evaluate, and even tougher to plug. And sensitive data? It's everywhere."

The report offers a detailed look at the total cost of ownership surrounding security technology and weighs the cost of "renting" tools against the cost of "owning" them.

"For most SMBs, the benefits of SaaS and third-party security fall into three areas: cutting down on the stress associated with managing complex security apps; getting up and running quickly; and letting you focus on your business without having to worry about installing updates," the report says.

The report estimates that a Web security solution would cost the typical SMB about $38,000 in the first year, while an SaaS solution that delivers many of the same capabilities would cost about $15,000. The report also offers a look at TCO for a five-year period.

Of course, SaaS solutions aren't completely automated, the report observes. Building a working solution means knowing what sensitive data you have, what regulatory rules your organization might be subject to, and where the critical data resides.

"In our experience, SMBs tend to have sensitive data on employees' home machines; on removable media; or if you use cloud computing, on 100 file servers scattered throughout the globe," the study says.

In addition to offering TCO data, the report walks the reader through the data analysis process to help identify the type and location of information that needs secure handling.

To download the full report, click here.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS












Featured Webcasts
Featured Whitepapers
Featured Reports
Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.