Users bank on managed security services

News
Jul 11, 20056 mins

More enterprise business customers are turning to managed security service providers to help them cope with the complexities of network security, especially when it comes to intrusion prevention.

More enterprise business customers are turning to managed security service providers to help them cope with the complexities of network security, especially when it comes to intrusion prevention .

MSSP offerings are expected to generate about $1 billion in spending this year, says Allan Carey, a program manager for business and continuity services at IDC. The $1 billion is part of an overall security services spending projection, which includes consulting, training, implementation and MSSP costs, of about $7.4 billion for 2005.

Security audits and regulatory compliance are just two of the reasons organizations are more interested in MSSP offerings, says Kelly Kavanagh, an analyst at Gartner. MSSP services can help with audit compliance through documented monitoring, reporting and remediation, he says.

Users have become more willing to outsource their security needs to a third party. “Over the past couple of years enterprise customers have become more comfortable with the level of maturity in the MSSP market,” Carey says.

Many organizations also don’t have the capital to deploy the hardware and software necessary to support their own intrusion detection, intrusion prevention, anti-distributed denial of service or other security services, he says.

Compliance was one of the key reasons why Boiling Springs Savings Bank switched to MSSP Perimeter Internetworking, which specializes in offering managed security services to small banks.

Boiling Springs is a $1.1 billion thrift with 14 locations in northeastern New Jersey that uses Perimeter’s intrusion-detection services, says Kenneth Emerson, director of strategic planning and CIO. Emerson says he sold the board of directors on Perimeter’s services by explaining that they are essentially an “insurance policy against lost customer confidence.”

About three years ago Boiling Springs turned to Perimeter to shore up the bank’s security support. Emerson says he had an ISP that knew security, but didn’t have a Level II Statement on Auditing Standard (SAS) review. This is a specialized audit that verifies a company’s operational and internal controls over processing user transactions.

“It’s up to me to engage a firm that has a SAS 70. If they don’t, then it’s up to me to have one done. They’re expensive – about $30,000 to $50,000,” Emerson says. “My ISP said they were looking into having one, but I needed something more proactive.”

Perimeter had the required audit.

Emerson says banks also are required to have annual penetration tests, which cost about $12,000 to $15,000. But because he’s using Perimeter’s intrusion-detection services and has no outward facing hosts to the Internet, he’s covered.

The bank has a centralized network set-up with all traffic coming through its headquarters in Rutherford. Boiling Springs has a dedicated frame relay connection to Perimeter from its headquarters and another to an ISP. In a hub-and-spoke architecture, each branch also has a dedicated frame connection to Rutherford. There is an ISDN backup at each site.

While AT&T provides the frame relay services, Perimeter actually worked with the carrier to have the services deployed and maintained, which was also an advantage because it reduces finger-pointing, he says. Emerson says Perimeter’s services are expensive, but that the bank saved money by teaming with a provider that had the appropriate audits in place and by eliminating the need to do penetration tests.

Other users are going with MSSPs to help manage intrusion-prevention systems. Intrusion-prevention services add an additional level of complexity, analysts agree, primarily because of the high number of false positives they produce.

Exchange Bank, a savings and loan with 20 branches in Sonoma County and headquarters in Santa Rosa, Calif., was using intrusion-detection services from SBC before the bank switched to Internet Security Systems (ISS). “Security was a sideline business for them and they weren’t doing a very good job,” says Bob Gligorea, information security officer at the bank.

“I would come in in the morning and look at our overnight reports and it would scare the hell out of me,” he says. “I would call [SBC’s] security network operations center and say, ‘Why didn’t you call me? Did you block this attack?’ And they would say they assumed I probably had the patches.”

“I don’t need a nice report of all of the bad things that happened while I was sleeping. I want my MSSP to actively protect our network,” he says.

Switching to ISS’ managed intrusion-prevention and managed firewall services about a year ago provided that. “Each morning I get reports on ISS’ portal on what actions were taken overnight. The service is constantly getting upgraded, which saves me so much time vs. having to stay on top of security changes myself,” he says.

The bank hasn’t been the victim of many attacks, but they do see a lot of scans.

“The first time I got a call from ISS was when we were working on a new Web trading tool that ran a legitimate scan of our network,” he says. They called to see if the scan was malicious, he says.

Exchange Bank selected ISS primarily because of its success in detecting computer vulnerabilities and also because it has worldwide coverage, he says.

Gligorea says he believes his network is better protected because ISS sometimes knows about vulnerabilities long before other security vendors.

“We couldn’t hire one person for what we’re paying on our managed service contract,” Gligorea says. The bank would likely have to hire nine people to have 24/7 coverage.

In addition to Perimeter Internetworking and ISS, there are security software and hardware companies that offer managed services such as Symantec and VeriSign. Then you have AT&T, MCI, Sprint and Equant, which are telecom veterans offering managed security services, although MCI now is somewhat different since it acquired MSSP NetSec earlier this year.

Then there are the big IT services firms such as Electronic Data Systems, Computer Sciences Corp., SAIC and Unisys, which all have managed security offerings.

And the niche or smaller players that only offer managed security services and some only to specific vertical markets, including Counterpane Internet Security, Perimeter Internetworking and Lurhq.

“There is no one best firm for anyone because each goes after different areas and customers with a slightly different emphasis on services,” Gartner’s Kavanagh says.

IDC’s Carey expects more advanced services from the MSSP market in the next 18 months and more industry consolidation.

Consolidation is one reason Gartner advises users to select an MSSP carefully. There are three areas users should consider: financial stability, breadth of services and Web-based tools.

An MSSP should have a “run rate of $20 million” in contract revenue to cover growth, according to the analyst firm. Users also should look for a service provider that has a wide variety of security services, including managed firewall, intrusion detection and prevention, consulting, anti-viral, vulnerability scanning and mitigation services.

The provider should offer a robust Web-portal and a variety of reporting and monitoring tools, Gartner says.