It can be challenging to find and retain a qualified chief information security officer (CISO), especially for small-sized enterprises with limited resources. As a result, some organizations are now choosing to outsource the job and hire a virtual CISO.
“Obviously, it's one of the hottest job markets that we've seen in a long, long time, and security is certainly no exception,” Thrive CTO Michael Gray told SDxCentral, adding that there is so much opportunity for CISOs out there, and building a security team is very difficult. “That's why a lot of people end up wanting to outsource CISO," he said.
In addition, as more organizations are committing to a remote or hybrid workforce, a virtual CISO position has become an option.
“Most companies under 1,000 people really just need a fractional CISO, they don't need a full-time CISO, nor can they afford one,” Gray said, adding that “The virtual CISO fits, I'd say, all the way up to maybe 2,500 employees.”
The benefit of having a virtual CISO is that the position is typically backed by a team of security experts, and as an objective outsider with experiences from other clients, it sees different environments, so a virtual CISO has a better idea of what's working and what’s best for the users, he added.
CISO’s role is to manage security programs from both technology and business sides, Gray pointed out, and the virtual one should be able to handle the entire security stack including roadmap, training, and day-to-day alerts.
In addition to helping address the burnout issues among security teams through outsourcing, the virtual CISO can save at least 60% of the cost depending on the size of the company, he claims. “What we do see is a lot of people who have a very heavy hourly usage in the beginning, maybe you're using 90% of their time for the first two months, and then over time that trims down to say 20% of the time maybe after six months.”
It’s “very similar to a consulting engagement but more on a monthly recurring basis,” Gray explained. The virtual CISO participates in or runs monthly meetings and helps create policies, but in the event of an incident, it’s “not so much to resolve the incident, but to be an advisor to the incident," he added.
Virtual CISO programs focus more on the preparation work, and the first thing they will work on is an incident response plan. In the event of a ransomware attack, a virtual CISO can be an incident manager, but it’s not their default role, Gray said.
“They're doing all the preparation and hopefully some prevention as opposed to being the one that's taking the call at two in the morning,” he added.
Since it is not a full-time employee as a traditional CISO, this brings concerns that they are only partially invested in the security program.
But, Thrive found outsourced CISOs have more process and structure since they need to deliver services at scale, Gray argues. “Moreover, full-time CISOs can struggle with impartiality since they are part of the overall security oversight. A third party can likely bring more independence when it comes to reviewing risks.”
Virtual CISO service has become the fastest growing product by far for managed service providers, according to Gray. Two years ago, around 5% of Thrive’s customer base adopted the virtual CISOs, and now it's grown up to 30%, he said
“I see more and more customers interested in vCISO as their first security service because, firstly, I want to get an understanding of what's going on, as opposed to just jumping into buying a SIEM [security information and event management] solution,” he said.
Comments