| | November - 2019ENTERPRISE SECURITY8In My OpinionScaling a Security Program with MSSPsBy Jeffrey W. Brown, CISO, Life & Retirement, AIG [NYSE: AIG]Outsourced information security services and managed security services providers (MSSPs) are a necessary component of most cybersecurity programs. Even large-scale financial institutions with fully-staffed internal security teams tend to have at least forensics and incident response experts on retainer in case internal teams are not enough to respond to a large or sophisticated attack. Security costs are skyrocketing and talent is still in extremely short supply. This is a global problem that only seems to be getting worse, even with new talent entering the industry every day. Qualified applicants that are affordable are even harder to come by, as even some junior and mid-level jobs are well into six figures, especially in urban centers. Indeed.com estimates that most security analyst jobs start around $80,000 and go up from there. The skilled hands-on workers are in short supply and are commanding higher salaries. Could MSSPs help fill some of these gaps? MSSPs are being used for everything from monitoring the security operations center (SOC) to handling the top job of CISO-as-a service with the rise of virtual CISOs (vCISOs). In the vCISO model, everything up to and including the top job can be outsourced. vCISOs can also simply "fill in" by providing leadership to your existing security team, interfacing with senior management and the Board or by filling in as an interim CISO while a permanent candidate is being sought. Outsourcing the top security job typically only makes sense for smaller companies. Having a senior executive with the overall responsibility for security who also has a seat at the business table is important. There are also risks to a complete CISO outsource, as you can create the perception that security risk has also been outsourced when the responsibility sits squarely with senior management and the board of directors.
<
Page 7 |
Page 9 >