{"id":20649,"date":"2016-10-06T13:15:13","date_gmt":"2016-10-06T20:15:13","guid":{"rendered":"http:\/\/www.enxmag.com\/twii\/?p=20649"},"modified":"2016-10-20T04:13:00","modified_gmt":"2016-10-20T11:13:00","slug":"expert-msps-and-tech-providers-will-see-more-security-concerns-from-customers","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/editors-blog\/2016\/10\/expert-msps-and-tech-providers-will-see-more-security-concerns-from-customers\/","title":{"rendered":"Expert: MSPs and Tech Providers Will See More Security Concerns from Customers"},"content":{"rendered":"<div id=\"attachment_20652\" style=\"width: 215px\" class=\"wp-caption alignleft\"><img aria-describedby=\"caption-attachment-20652\" loading=\"lazy\" class=\"wp-image-20652 size-full\" src=\"http:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Michael_Buratowski_205.jpg\" alt=\"michael_buratowski_205\" width=\"205\" height=\"205\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Michael_Buratowski_205.jpg 205w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Michael_Buratowski_205-150x150.jpg 150w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Michael_Buratowski_205-380x380.jpg 380w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Michael_Buratowski_205-200x200.jpg 200w\" sizes=\"(max-width: 205px) 100vw, 205px\" \/><p id=\"caption-attachment-20652\" class=\"wp-caption-text\">Michael Buratowski<\/p><\/div>\n<p>If you sell any services or products that are delivered through or connected to the internet, then be prepared to face more questions from your customer base about security in the coming year. That was the message that Michael Buratowski, senior VP of Cybersecurity Services at Fidelis Cybersecurity, gave the audience at Continuum\u2019s Navigate conference last week.<\/p>\n<p>Don\u2019t think your clients are safe from cyber attack because of their size. According to Symantec\u2019s 2015 Internet Security Report, 43 percent of all spear-phishing attacks, where email-spoofing is used in an attempt to gain access to data, were against companies with fewer than 250 employees. Buratowski cited other statistics to show why every business should worry about cybersecurity:<\/p>\n<ul>\n<li>The average cost of a lost or stolen record is $217<\/li>\n<li>Hiring people to hack an organization is cheap: $500 to hack a website, $200 to hack an email address, or just $50 per day to do a persistent denial of service attack.<\/li>\n<li>There were 362,000 ransomware attacks in 2015, and they are growing at a rate of 35 percent.<\/li>\n<\/ul>\n<div id=\"attachment_20651\" style=\"width: 403px\" class=\"wp-caption alignright\"><img aria-describedby=\"caption-attachment-20651\" loading=\"lazy\" class=\"wp-image-20651\" src=\"http:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Cybersecurity-Mike-Buratowski-Navigate-2016-300x169.jpg\" alt=\"cybersecurity-mike-buratowski-navigate-2016\" width=\"393\" height=\"221\" srcset=\"https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Cybersecurity-Mike-Buratowski-Navigate-2016-300x169.jpg 300w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Cybersecurity-Mike-Buratowski-Navigate-2016-768x432.jpg 768w, https:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2016\/10\/Cybersecurity-Mike-Buratowski-Navigate-2016-1024x576.jpg 1024w\" sizes=\"(max-width: 393px) 100vw, 393px\" \/><p id=\"caption-attachment-20651\" class=\"wp-caption-text\">Most companies don&#8217;t have the people, technology, and processes in place to adequately protect against cyber attack.<\/p><\/div>\n<p>Part of the reason Buratowski sees demand for security services going up are concerns over liability. Companies that are breached are at a disadvantage when sued if their security was sub-standard. \u201cFocus on what is responsible,\u201d said Buratowski. \u201cThat\u2019s the sweet spot. You can defend yourself in court if you can say I did what was reasonably expected for a company of my size and revenue.\u201d By \u201cresponsible,\u201d Buratowski means that your security needs to be somewhere between the minimal standards of security compliance and total lock-down.<\/p>\n<p>This trend could be a boon for managed services providers (MSPs). Buratowski quoted a Gartner report that predicts 50 percent of MSPs will offer managed detection and recovery (MDR) services by 2020. Separately, Continuum announced it will be releasing security services that its MSP partners can deliver through its platform.<\/p>\n<p>Early detection is critical. \u201cYou need to see [an intrusion] as early as possible,\u201d said Buratowski. \u201cThe time from initial breach to discovery averages about 200 days.\u201d During that time, the intruder has time to gain fuller access to an organization and do more damage.<\/p>\n<p>Just as important as preventing security incidents is having a plan of action in the event that you or a client has one. \u201cYou need a strong incidence response team,\u201d said Buratowski. That team would include someone at the client, legal counsel, law enforcement, and any third parties that you involve. He suggests establishing a relationship with a legal expert so that you can bring that person in quickly when the need arises. He also told the audience to find out who is responsible for handling cyber crimes at the local police. Building a relationship with that person could be critical when a breach happens.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you sell any services or products that are delivered through or connected to the internet, then be prepared to face more questions from your customer base about security in the coming year. That was the message that Michael Buratowski, senior VP of Cybersecurity Services at Fidelis Cybersecurity, gave the audience at Continuum\u2019s Navigate conference last week. Don\u2019t think your clients are safe from cyber attack because of their size. According to Symantec\u2019s 2015 Internet Security Report, 43 percent of all spear-phishing attacks, where email-spoofing is used in an attempt to gain access to data, were against companies with fewer than 250 employees. Buratowski cited other statistics to show why every business should worry about cybersecurity: The average cost of a lost or stolen record is $217 Hiring people to hack an organization is cheap: $500 to hack a website, $200 to hack an email address, or just $50 per day to do a persistent denial of service attack. There were 362,000 ransomware attacks in 2015, and they are growing at a rate of 35 percent. Part of the reason Buratowski sees demand for security services going up are concerns over liability. Companies that are breached are at a disadvantage when sued if their security was sub-standard. \u201cFocus on what is responsible,\u201d said Buratowski. \u201cThat\u2019s the sweet spot. You can defend yourself in court if you can say I did what was reasonably expected for a company of my size and revenue.\u201d By \u201cresponsible,\u201d Buratowski means that your security needs to be somewhere between the minimal standards of security compliance and total lock-down. This trend could be a boon for managed services providers (MSPs). Buratowski quoted a Gartner report that predicts 50 percent of MSPs will offer managed detection and recovery (MDR) services by 2020. Separately, Continuum announced it will be releasing security services that its MSP partners can deliver through its platform. Early detection is critical. \u201cYou need to see [an intrusion] as early as possible,\u201d said Buratowski. \u201cThe time from initial breach to discovery averages about 200 days.\u201d During that time, the intruder has time to gain fuller access to an organization and do more damage. Just as important as preventing security incidents is having a plan of action in the event that you or a client has one. \u201cYou need a strong incidence response team,\u201d said Buratowski. That team would include someone at the client, legal counsel, law enforcement, and any third parties that you involve. He suggests establishing a relationship with a legal expert so that you can bring that person in quickly when the need arises. He also told the audience to find out who is responsible for handling cyber crimes at the local police. Building a relationship with that person could be critical when a breach happens.<\/p>\n","protected":false},"author":115,"featured_media":20652,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[80,1638],"tags":[2832,2411,527],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/20649"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/115"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=20649"}],"version-history":[{"count":3,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/20649\/revisions"}],"predecessor-version":[{"id":20667,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/20649\/revisions\/20667"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/20652"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=20649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=20649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=20649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}