Showing posts with label Outsourcing. Show all posts
Showing posts with label Outsourcing. Show all posts

Sunday, May 24, 2015

Outsourcing/Offshoring and Cyber Threat - Why and How?

Outsourcing/Offshoring are solutions for lot of issues that businesses face, for example: - Cheaper human resources, - Infrastructure convenience, - Knowledge & skills and - Higher growth potential of businesses. By outsourcing the day to day back-office tasks, the business owner has more time to focus on generating income. However, taking into consideration today’s cyber threats, if cyber security standards are not uniformly upheld by the third party, the outsourcing/offshoring of business processes and supply does not come without risks. Risks of: - Identity theft, - Loss or destruction of sensible information and intellectual property, - Unauthorized access to the network service, - Infection with malicious code etc. Moreover, key risk that many businesses face when outsourcing/offshoring is that they themselves are not aware of what controls and policies should be adhered to by the third party. The real question ponder upon is: - Are financial saving the sole aim of outsourcing or has cyber security been factored into the third party considerations? - Even if cyber security has been taken into account, is it purely from a technical perspective, or has the effect on the overall business value chain been considered?

Outsourcing/offshoring are the realities of today’s businesses and it is essential for the decision makers to do the diligence in terms of risk assessment. Remember, there is always an answer to a problem, and threats to cyber security from outsourcing/offshoring can also be reduced, if not fully mitigated, by implementing various countermeasures. So what is the answer to the Cyber Security risk posed by Outsourcing/Offshoring? - Implement cyber security policies, procedures and guidelines for outsourcing / offshoring arrangements in accordance with the industry best practices i.e. NIST Cyber Security Frameworks, ISO 27K series and also includes risk assessment, threat profiling with respect to vendor / geographical locations respectively. - Ensure to contractually embed the necessary information security, business continuity and privacy controls to ensure continued compliance with internal policy and regulatory burdens. - Consider non-sensitive operational areas to be outsourced/offshored. Don't outsource something just because you don't want to do it. Sometimes there are things you don't want to do but they are important to your core business." Even experienced optimists accept that an information security incident is inevitable as 100% security is unachievable and there is no silver bullet; recognition of a long-term risk based approach is necessary. An example of outsourcing might be the IT support for your network. You may not be able to afford or need a full-time IT person, and it is easier to change to an outsourced provider with the right skill set as your IT needs change.