BreachExchange mailing list archives

Contracting for Cyber-Security Service Agreements


From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Wed, 21 Oct 2015 17:51:00 -0600

http://www.baselinemag.com/security/contracting-for-cyber-security-service-agreements.html

When wireless carrier T-Mobile discovered earlier this month that personal
data entrusted to it by some 15 million customers had been stolen from
servers maintained by its credit processor, Experian, T-Mobile learned a
hard but increasingly familiar lesson: A company’s data security is only as
strong as the weakest link in its supply chain.

In the ordinary course of 21st century business, companies often expose
their data to other companies, particularly service providers. Those
providers may be engaged specifically to process data (as Experian was by
T-Mobile), or they may simply be given access for incidental reasons.
Either way, any weakness in the security practices of a company’s service
providers can expose the company to cyber-attacks as surely as if the
weakness were its own.

Data breaches have grown so common that they seem almost inevitable, but
that doesn’t mean companies should stop doing everything they can to avoid
them. The costs are real: Data breaches damage brands and reputations,
disrupt business operations and relationships, require costly
investigations, and invite a range of threatening legal responses,
including consumer class actions, shareholder derivative suits, and FTC and
other regulatory actions.

All told, the average data breach costs more than $3.8 million. When a data
breach does happen, having a service provider involved adds complications
that, according to one estimate, increase the cost of breach by an average
of 10 percent.

The good news is that by contracting well, you can reduce the likelihood
and severity of these risks. In contracting with a new service provider (or
renegotiating with an existing one), a company intent on minimizing its
data breach risks should focus on three questions.

First, is the provider capable of complying with adequate data protection
and privacy standards? Second, will the provider agree to comply with those
standards? And third, will the provider remain properly motivated to live
up to its agreement? In summary, contracting for cyber-security is
primarily a matter of selecting the right provider, securing the right
commitments and setting the right incentives.

Selecting the Right Provider

To weed out risky providers, you must first know the challenges you face.
The contracting team needs to align with the company’s cyber-security
experts.

As first steps, identify the types of data that the provider might access,
understand the nature of the cyber-security risk for each type of data, and
find the relevant parts of your information security plan. Then, consider
whether the risks might be mitigated through technical or operational
measures, such as encrypting data or limiting access to it.

If there is a data security concern, then any Request for Information (RFI)
or other preliminary market review should include questions about data
security practices. Many companies have form questionnaires based on their
own information security plans, and, in the absence of such a form,
requests for information about security certifications may be a fast
approach.

For high-risk data, consider using security audits and reviews as part of
any initial site visit, just as you would review any other aspect of
production. Estimate what it will cost to be sure that the equivalent level
of security is maintained over time.

Securing the Right Commitments

When negotiating a contract with a service provider, you can mitigate the
risk by obtaining general data security commitments. These might include
assurances to:

· Avoid disclosing your confidential information

· Keep your data secure (whether or not it's confidential)

· Comply with industry standards such as ISO 27001

· Comply with privacy and data security laws

· Comply with your written information security policies

· Implement and maintain specified physical and operational security
measures.

However, there are opportunities throughout the contract to include
commitments that reduce cyber-security risk. These include:

· Restrictions on subcontracting, including requirements to flow down data
security clauses

· Background checks and personnel screening

· Data minimization obligations (including those under records retention
policies)

· Limitations on access to systems

· Adequate cyber-liability coverage on a primary basis

· Restrictions on secondary uses of data (including aggregated, derived or
anonymized data).

Because the cyber-threat is constantly evolving, also consider commitments
to evolve cyber-security protections. These might be general commitments to
evolve as threats evolve, or you might obtain options to allow you to
purchase specific additional cyber-security protections at reasonably firm
prices.

Setting the Right Incentives

Commitments help, but you also want your service providers to wake up every
morning thinking about how to prevent a data breach, and, if one occurs,
how to minimize the cost. You can do that by creating incentives, such as
clauses that require the following:

· Reimbursement for the cost of audits that detect security failures

· Reimbursement for legally mandated costs of security breaches, such as
data breach notification to consumers

· Reimbursement for customary additional actions, such as investigation,
call centers, credit monitoring services, credit card replacements, etc.

· Reimbursement for other damages, perhaps those subject to a liability
waiver or cap

· Termination rights triggered by breaches (e.g., deeming a data security
incident involving loss of sensitive data a material breach).

As much as possible, these incentives should be designed to create an
incentive not only to avoid causing security incidents but also to prevent
them. Service providers, of course, will seek to limit their liability to
security incidents that they cause.

Risk has always been a part of business, as has learning how to cope with
new categories of risk when they emerge. Cyber-risk is just such an
emerging category, and businesses are understandably still learning how to
manage it.

However, as the novelty wears off, there is dwindling patience in the
markets and the courts for businesses that don’t take sensible steps to
minimize their risk of data breaches. Contracting for cyber-security
commitments in service provider relationships is as sensible as such steps
get, and there’s no excuse for not doing it right.
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss
For inquiries regarding use or licensing of data, e-mail
        sales () riskbasedsecurity com 

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus 
on the right security.  If you need security help or want to provide real risk reduction for your clients contact us!

Current thread: