Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/25/2008
05:22 AM
50%
50%

Time to Implement Security as a Service?

Software as a Service (SaaS) has been gaining acceptance among small and medium businesses because it eases maintenance and deployment requirements. Having been widely implemented in areas, such as Customer Relationship Management, it is now advancing into the security market.

Software as a Service (SaaS) has been gaining acceptance among small and medium businesses because it eases maintenance and deployment requirements. Having been widely implemented in areas, such as Customer Relationship Management, it is now advancing into the security market.ScanSafe is one of the companies delivering security SaaS solutions. Its Anywhere+ service delivers Web security features, such as enforcing a companys acceptable Internet usage policies regardless of where employees may be located. Such services have a couple of appealing features. The first is inherent with any SaaS solution, simplicity. As computer software has become more complex, companies have had trouble keeping up with an unceasing barrage of updates. With SaaS, a vendor takes over that challenge.

In addition, security checks are becoming more difficult to deploy because of employees increasing mobility. A ScanSafe survey found that 95% of companies now have at least 10% of their staff who work remotely on a regular basis. Employees are now stationed at hotels, customer sites, airports, remote offices, and their homes. They never know what type of network connection may be available, and sometimes, items, such as firewalls, have to be deactivated in order for them to be able to access the Internet. Consequently, their systems become susceptible to various types of malware attacks, such as viruses and spyware. A SaaS service makes it more likely that they will have the proper security checks in place as they surf the Web.

These services do come with a few caveats. Security SaaS is an emerging area, so the first wave of customers may encounter some unexpected glitches, which are common with new software. The service offerings are not as broad as the packaged software solutions that are now available. Only a few suppliers, such as Qualys and MessageLabs, are in the market, so the vendors long term viability is an open question. However, with security challenges growing more complex each day, investigating these services is something that a small and medium business should put on its To Do list.

Are you using a SaaS service? What do you see as their benefits? How comfortable or uncomfortable would you be in deploying a security SaaS solution?

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
5 Common Errors That Allow Attackers to Go Undetected
Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9268
PUBLISHED: 2020-02-18
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
CVE-2020-9269
PUBLISHED: 2020-02-18
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
CVE-2020-9270
PUBLISHED: 2020-02-18
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
CVE-2020-9271
PUBLISHED: 2020-02-18
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
CVE-2020-9265
PUBLISHED: 2020-02-18
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username.