“These are generally not in any way, shape or form, internet-facing but organisations are realising from business continuity analysis and the business impact analysis that goes with that that these are really crucial to the business – so they’re treating them as if they were.”

EY is seeing much more application security risk assessment being carried out on those internal applications from two viewpoints, according to Callaghan.
“The first is from a purely ethical hacking point of view– tell me if my system is configured securely or whether the business controls that I’ve got in place can be circumvented. The second is more complex, and is best seen from a pure development point of view.”
Organisations are keen to get more value out of the security testing they’re doing and don’t want to diagnose the same problems time and time again with, for example, web applications. Instead, said Callaghan, they are spending more further upstream in the software development life-cycle so that problems can be identified earlier.
“They’re interested in identifying problems before they actually become manifest and go into production because as we all know, fixing mistakes before things go into deployment is much cheaper than fixing them when they’re actually in place.”
Supplier risk
Another security related activity that is being outsourced as a service is supplier risk management, something that Callaghan says it is increasingly common to find companies engaging in.
“Supplier risk management has become a relatively traditional activity over the last four or five years as all large companies now operate within an ecosystem of suppliers and business partners, some of which can have access to quite critical sensitive data and sensitive customer-facing business functions.”
“Understanding the risk exposure and understanding the controls that need to be put in place at on-boarding time for those suppliers and also monitored on an ongoing basis is something that organisations are increasingly seeking to outsource because it’s quite a repetitive activity. The independent viewpoint of a partner works quite well with it.”
In addition, EY also offers a managed security operations centre service that targets larger clients which already have sophisticated monitoring capability.
“It’s for businesses that recognise that they’re not getting the best out of it so we actually partner with a lot of these companies to build better processes, to make sure that the organisation is right and actually implement a technology stack to help them operate that function.”








Ltd