Buying cybersecurity

What cybersecurity help does my business need?

Knowing that you need some cybersecurity help is one thing. Knowing what to ask for is quite another.

Perhaps a customer has sent you a security questionnaire that nobody quite knows how to answer. Your investors have started asking more detailed questions. Someone has decided SOC 2 needs to happen. You're about to launch a new product and want somebody independent to look at it. Or security has simply become big enough that managing it between other jobs no longer feels particularly sensible.

Then you start looking for help.

Suddenly you're choosing between penetration testing, vulnerability assessments, GRC consultants, virtual CISOs, cloud security specialists, application security, incident response, compliance consultants and a growing collection of acronyms.

That's a peculiar way to buy anything.

You wouldn't expect someone with a leaking roof to diagnose the exact roofing discipline required before they're allowed to speak to somebody who can help. Yet cybersecurity buyers are routinely expected to understand the solution before they've properly diagnosed the problem.

There is a simpler place to start.

Start with what's happening, not what the service is called

Before deciding what cybersecurity service you need, describe the situation you're trying to deal with.

That might sound obvious, but it changes the conversation.

Instead of asking:

Do we need a vCISO?

Start with:

Nobody here really owns security and it's becoming difficult to manage.

Instead of:

Should we get a pentest?

Start with:

We're about to launch this product and want independent assurance that we've not missed something important.

And instead of:

Do we need GRC?

Start with:

A major prospect wants evidence of our security controls and we're struggling to provide it.

Those problems may eventually lead to a vCISO, penetration tester or GRC specialist. But starting with the situation gives you a much better chance of finding the right expertise.

A customer is asking difficult security questions

This is a common point at which smaller companies discover that their security has become a commercial issue.

A prospect might send a detailed security questionnaire, ask for policies and evidence, want to understand how you manage risk, or make a recognised security standard part of the deal.

The right help depends on what they're asking for and what you already have.

If the problem is demonstrating controls, policies and governance, you may need GRC or customer assurance support.

If the customer requires a particular certification or framework, you may need someone experienced with ISO 27001, SOC 2, Cyber Essentials or the relevant requirement.

If you're repeatedly encountering these questions and nobody internally owns the overall security programme, the underlying need may be broader than completing one questionnaire.

The questionnaire is sometimes the symptom rather than the problem.

You're worried about the security of your product

Perhaps you're launching something new, making a significant change, preparing for an enterprise customer or simply haven't had an independent pair of eyes on the product for a while.

This is where terms such as penetration testing, application security, cloud security, vulnerability management and security assessment start appearing.

They aren't interchangeable.

A penetration test is a focused exercise designed to identify exploitable weaknesses in a defined target. It doesn't automatically tell you whether the wider way you build, deploy and operate your product is appropriate.

Application security expertise may be more useful if you need to improve security throughout development rather than test a finished system.

Cloud security support may be appropriate when the concern sits in your architecture, configuration, identities or cloud environment.

Start with what you want to understand or achieve. Then decide which discipline gets you there.

You've been told you need to become compliant

“Compliance” can cover an enormous amount of territory.

You might have a contractual requirement from a customer, an industry obligation, a certification you're pursuing or a broader need to demonstrate that sensible controls exist.

Before engaging anyone, establish what is driving the requirement.

There is little value in racing towards a certification because somebody vaguely suggested that you “need ISO” if your immediate commercial requirement is something entirely different.

Good compliance and GRC support should help you understand the requirement, identify the gap between where you are and where you need to be, and build an achievable route between the two.

The destination matters before you start buying maps.

Something has happened

A suspected breach, compromised account, ransomware incident, leaked credential or unexplained activity is different from routine security improvement.

You may need incident response or digital forensics expertise, particularly where the situation is active, the scope is unclear or sensitive data may be involved.

Speed matters, but so does getting appropriate help.

Avoid turning an active incident into a shopping exercise involving twelve tabs and a comparison spreadsheet. Establish what has happened, preserve relevant evidence where possible and find appropriately experienced incident support.

Once the immediate situation is under control, the work often changes. Recovery, remediation and understanding how to reduce the chance of recurrence can require different expertise from the people dealing with the incident itself.

Nobody really owns cybersecurity

In smaller businesses, security often starts as part of somebody else's job.

The CTO handles some of it. IT handles another part. Engineering makes security decisions. Someone in operations deals with questionnaires. The CEO gets dragged in when a large customer asks an awkward question.

That can work for quite a while.

Eventually, however, the number of security decisions grows while ownership remains fuzzy.

This is where security leadership or vCISO support can make sense.

A vCISO can provide experienced security leadership without the business immediately hiring a full-time CISO. Depending on the engagement, that might include setting priorities, building a security programme, advising leadership, supporting customer requirements, coordinating specialist suppliers and helping the business understand which security investments are worth making.

But not every company with a security problem needs a vCISO.

If your immediate requirement is a clearly defined piece of specialist work, hiring the specialist directly may be the better answer.

Sometimes you don't need outside cybersecurity help

This possibility tends to disappear from conversations about buying cybersecurity services.

Not every security question requires a consultant.

You may already have the expertise internally. The problem might be small enough for your existing team to resolve. You might need to improve a process rather than bring in another supplier.

And sometimes the sensible answer is to wait.

The purpose of diagnosing the problem first isn't to find something to buy. It's to work out what, if anything, would help.

That distinction matters.

You might need more than one kind of expertise

Cybersecurity problems don't respect service categories.

A company preparing for an enterprise customer might discover it needs some GRC support, an independent test of its product and somebody to take longer-term ownership of security.

An incident might expose weaknesses in identity management that subsequently require technical remediation and improvements to operational processes.

This doesn't necessarily mean assembling an army of consultants.

It means understanding the problem well enough to distinguish what needs attention now, what can wait and which skills are appropriate for each part.

Security Compass: start with the problem

This is why we built Security Compass. It's a free cybersecurity guidance tool for businesses that know something needs attention but don't necessarily know what kind of security service to look for.

You don't need to know your pentest from your GRC assessment before you start. Tell Security Compass what's going on, answer a few questions and it will point you towards the type of cybersecurity expertise that may make sense, explain why, and give you a useful next step.

It takes about two minutes and you don't need an account.

Not sure whether you need help at all? Start with the Startup Security Check instead.

Common questions

What cybersecurity help does a small business need?

It depends on the problem the business is trying to solve. Common needs include product security testing, cloud or application security, compliance and GRC support, incident response, security leadership and help responding to customer security requirements. Start by defining the situation rather than choosing a service category.

How do I know if my business needs a penetration test?

A penetration test can be useful when you need an independent assessment of whether weaknesses in a defined system or application can be exploited. It may be requested by a customer or compliance requirement, or used as part of product security assurance. It is not a substitute for every other form of security assessment.

When does a small business need a vCISO?

A vCISO can make sense when cybersecurity requires ongoing leadership and coordination but the business doesn't need, or isn't ready for, a full-time CISO. If the requirement is a single specialist task, a specialist engagement may be more appropriate.

What if I don't know which cybersecurity service I need?

Start with the business problem. Security Compass asks about what is happening and uses your answers to point towards potentially relevant types of cybersecurity expertise. You don't need to select a cybersecurity service before using it.

Is Security Compass free?

Yes. Security Compass is free to use, takes about two minutes and does not require a Heelr account.

Does Security Compass assess my company's security?

No. Security Compass is a guidance tool designed to help identify potentially relevant types of cybersecurity expertise. It is not a security audit, professional assessment or certification of your security posture.

Related