BreachExchange mailing list archives
Contracting for Cyber-Security Service Agreements
From: Audrey McNeil <audrey () riskbasedsecurity com>
Date: Wed, 21 Oct 2015 17:51:00 -0600
http://www.baselinemag.com/security/contracting-for-cyber-security-service-agreements.html When wireless carrier T-Mobile discovered earlier this month that personal data entrusted to it by some 15 million customers had been stolen from servers maintained by its credit processor, Experian, T-Mobile learned a hard but increasingly familiar lesson: A company’s data security is only as strong as the weakest link in its supply chain. In the ordinary course of 21st century business, companies often expose their data to other companies, particularly service providers. Those providers may be engaged specifically to process data (as Experian was by T-Mobile), or they may simply be given access for incidental reasons. Either way, any weakness in the security practices of a company’s service providers can expose the company to cyber-attacks as surely as if the weakness were its own. Data breaches have grown so common that they seem almost inevitable, but that doesn’t mean companies should stop doing everything they can to avoid them. The costs are real: Data breaches damage brands and reputations, disrupt business operations and relationships, require costly investigations, and invite a range of threatening legal responses, including consumer class actions, shareholder derivative suits, and FTC and other regulatory actions. All told, the average data breach costs more than $3.8 million. When a data breach does happen, having a service provider involved adds complications that, according to one estimate, increase the cost of breach by an average of 10 percent. The good news is that by contracting well, you can reduce the likelihood and severity of these risks. In contracting with a new service provider (or renegotiating with an existing one), a company intent on minimizing its data breach risks should focus on three questions. First, is the provider capable of complying with adequate data protection and privacy standards? Second, will the provider agree to comply with those standards? And third, will the provider remain properly motivated to live up to its agreement? In summary, contracting for cyber-security is primarily a matter of selecting the right provider, securing the right commitments and setting the right incentives. Selecting the Right Provider To weed out risky providers, you must first know the challenges you face. The contracting team needs to align with the company’s cyber-security experts. As first steps, identify the types of data that the provider might access, understand the nature of the cyber-security risk for each type of data, and find the relevant parts of your information security plan. Then, consider whether the risks might be mitigated through technical or operational measures, such as encrypting data or limiting access to it. If there is a data security concern, then any Request for Information (RFI) or other preliminary market review should include questions about data security practices. Many companies have form questionnaires based on their own information security plans, and, in the absence of such a form, requests for information about security certifications may be a fast approach. For high-risk data, consider using security audits and reviews as part of any initial site visit, just as you would review any other aspect of production. Estimate what it will cost to be sure that the equivalent level of security is maintained over time. Securing the Right Commitments When negotiating a contract with a service provider, you can mitigate the risk by obtaining general data security commitments. These might include assurances to: · Avoid disclosing your confidential information · Keep your data secure (whether or not it's confidential) · Comply with industry standards such as ISO 27001 · Comply with privacy and data security laws · Comply with your written information security policies · Implement and maintain specified physical and operational security measures. However, there are opportunities throughout the contract to include commitments that reduce cyber-security risk. These include: · Restrictions on subcontracting, including requirements to flow down data security clauses · Background checks and personnel screening · Data minimization obligations (including those under records retention policies) · Limitations on access to systems · Adequate cyber-liability coverage on a primary basis · Restrictions on secondary uses of data (including aggregated, derived or anonymized data). Because the cyber-threat is constantly evolving, also consider commitments to evolve cyber-security protections. These might be general commitments to evolve as threats evolve, or you might obtain options to allow you to purchase specific additional cyber-security protections at reasonably firm prices. Setting the Right Incentives Commitments help, but you also want your service providers to wake up every morning thinking about how to prevent a data breach, and, if one occurs, how to minimize the cost. You can do that by creating incentives, such as clauses that require the following: · Reimbursement for the cost of audits that detect security failures · Reimbursement for legally mandated costs of security breaches, such as data breach notification to consumers · Reimbursement for customary additional actions, such as investigation, call centers, credit monitoring services, credit card replacements, etc. · Reimbursement for other damages, perhaps those subject to a liability waiver or cap · Termination rights triggered by breaches (e.g., deeming a data security incident involving loss of sensitive data a material breach). As much as possible, these incentives should be designed to create an incentive not only to avoid causing security incidents but also to prevent them. Service providers, of course, will seek to limit their liability to security incidents that they cause. Risk has always been a part of business, as has learning how to cope with new categories of risk when they emerge. Cyber-risk is just such an emerging category, and businesses are understandably still learning how to manage it. However, as the novelty wears off, there is dwindling patience in the markets and the courts for businesses that don’t take sensible steps to minimize their risk of data breaches. Contracting for cyber-security commitments in service provider relationships is as sensible as such steps get, and there’s no excuse for not doing it right.
_______________________________________________ Dataloss Mailing List (dataloss () datalossdb org) Archived at http://seclists.org/dataloss/ Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss For inquiries regarding use or licensing of data, e-mail sales () riskbasedsecurity com Supporters: Risk Based Security (http://www.riskbasedsecurity.com/) YourCISO is an affordable SaaS solution that provides a comprehensive information security program that ensures focus on the right security. If you need security help or want to provide real risk reduction for your clients contact us!
Current thread:
- Contracting for Cyber-Security Service Agreements Audrey McNeil (Oct 22)
