Withdrawal from market
The undecided on the topic shouldn’t necessarily jump in with both feet just yet though with several experts who spoke with TechPro indicating an interesting 18 months lies ahead in the space. Interestingly, for instance, Threatscape’s Williams said that during that timescale he wouldn’t surprised if “smaller MSS players, who in reality mostly just assist clients in managing their security solutions, either withdraw from MSS entirely or partner with one of the global players with proven monitoring capability”.
This, he said, was based on the increasingly difficult challenge of handling the larger and larger volumes of log data being generated by customer systems and analysing it in “near real time to spot anomalies and confirm security incidents”.
Commtech’s Harvey added that those MSS providers who do stay in the market will be focused on being able to respond to the changes in “attack focus”, wherein “the attackers will get more specific, both in terms of their objective and attack strategies”. Said Harvey, “Attackers now know whom and how they would attack and they are changing their attack strategies to hit straight on the bullseye rather than shooting in the dark.”
“Many companies will likely use a gradual process when moving towards MSS. You have to think what do the customers want to pay for, and at the minute you’re looking at your endpoint, traditional antivirus, antimalware and encryption. Then you’re looking at firewall, unified threat management et cetera. You’re seeing more drive from the end users asking for these to be taken out of their internal resources,” Michael Conway, Renaissance
He added that in addition to this the volume of data to be protected will obviously continue to explode and continue “to be a bigger and bigger problem for network administrators”. Another “key area” to watch out for, said Harvey, is a greater interest in “context-aware security”, which enables faster decision making and action with the security intelligence it offers.
Competitor attacks
IBM’s Hickson also looked towards the types of attacks companies may face as being very influential on how the MSS market develops into 2015. “The latest crop of criminal enterprises is serving up ‘attacks as a service’,” said Hickson, “however it’s not all criminals or hooligans who are making these attacks on company sites – it’s not unheard of attacks by a competitor to make businesses inaccessible to other users.”
For his part, Cashman of Logicalis Ireland said that one particular trend to note in this sector over the coming year will be an increased number of companies using the ISO27001 information security system framework as a basis to structure their approach to security. For Logicalis, and others, this may lead to significant increases in take up for security information and management as a service to help against “the myriad of threats both external and internal that can lead to a security breach”, said Cashman.
Mobile threat
Almost every MSS industry voice who spoke with TechPro was keen to emphasise that the increasing influence mobility will have on the MSS industry. As Hickson noted, “While mobile devices can certainly pose new threats to enterprise data, these threats may be different than what you expected”.
Explaining further, Hickson said the biggest risk to companies is not the data contained on these devices, rather it is the credentials. “Mobile devices contain a trove of personal information, which can allow for further social engineering to mount new or deeper attacks into a company. The other major threat on mobile devices is applications that have been cracked and redistributed through rogue app stores,” he said.
Qualcom’s Carragher added that “ease of access to corporate data” provided for by mobility options will inevitably lead towards more managed services in this space. While mobile device management (MDM) is widely acknowledged as being a service that’s still very much finding its feet in terms of real effectiveness, as more robust solutions appear on the market “managed security providers have in-depth knowledge of this technology and the capabilities to implement and manage it effectively”.
“IT security teams have more issues than time to address and it is not the breadth of issues it also the depth and the diversity of the security risks. Using MSS for their IT security solution companies can either complement their existing security operations centre or completely outsource it,” Bryan Hickson, IBM
Meanwhile for Smith, alongside the mobile MSS question the next year or so will see plenty of discussion around “threat intelligence, security analytics and big data, as the industry explores how to make the most of these technologies”.
Developments may be led, he said, by the fact that “when customers experience a security incident it is no longer enough to simply offer a technical explanation”.
“Companies increasingly want to know how breaches will impact business and what they can do to limit negative repercussions – and we expect to see this more and more over the next 18 months,” said Smith.








Ltd