You are here: silicon.com > Software > Security Strategy

Security Strategy

Reuters outsources security monitoring

Cost and compliance burden drive the move…

By Andy McCue

Published: 10 January 2005 09:25 GMT

Reuters says that it has improved its IT security controls by outsourcing the monitoring of critical network intrusion detection sensors and firewalls to NetSec in a six-figure deal.

NetSec will be take the raw feed from the intrusion detection sensors and firewall logs, analyse the data and then go back to Reuters with custom reports and details of any unusual events or alarms that need attention.

Malcolm Kelly, global IT security director at Reuters, told silicon.com the move was partly driven by the knock-on effect of new financial and compliance regulations on Reuters' customers.

"We are under increasing pressure from customers and clients - especially the banks - who want to know what our security controls are. A lot of that is because of regulation requirements. Customers expect it of us," he said.

The other major factor was running such a function in-house and deploying IT security staff on work that is considered low-level and mundane.

"It is much more expensive to set up a dedicated function ourselves. We've never had a dedicated sensor monitoring function because of the difficulty retaining the skills in-house," he said.

Reuters has so far limited the use of outsourcing and managed services for IT security to the monitoring of new threats and vulnerabilities, some internet-facing systems and penetration testing.

But despite the growing interest in managed security services, Kelly said he would not consider handing over control of core security functions to a third party.

"I'd only outsource the more routine monitoring, low-level stuff where we'd never keep people interested in the work," he said.

For the lowdown on managed security services check out the silicon.com Cheat Sheet on the subject.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

IT Security analyst - Security qualified - Wintel - hands on - BANKING

Encryption Monitoring, Alerting and Auditing (SIEM) Directory Services Intrusion Prevention/Detection Systems Security Protocols ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

S55185 Quality Lead

As the Units Quality Lead, you will be responsible for the following activities: - Interaction with key stakeholders to coordinate activities related ...

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.





Quick Sitemap Links: