In Brief
MSSP Liability: A Pipe Dream?
If a security incident occurs, is your managed security service provider liable for the damages?
By Sarah D. Scalet
July 12, 2007 — CSO — If a security incident occurs, is your MSSP liable for the damages? Not likely.
So you decide to get rid of your boxes and blinking lights and have your telecom provider handle security in the cloudand something bad gets through anyway. Can you hit up your managed security service provider for damages?
Hardly. There is no one in the industry that will take on a liability SLA, says Stan Quintana, vice president of AT&T Security Services. What the industry is doing, however, is putting in place SLAs to compensate or give back some of the fees.
John Pescatore, a VP at Gartner, compares this arrangement with the contract home buyers sign when they have a house inspection done. When you go to buy a house, you have to get a termite inspection, he explains. You read through all the contract and it says, at the bottom, even if we say there are no termites, if your house falls down the next day [because of termites], well give you back the $49 that you paid for the inspection.
As far as collecting any more money for damages than the service fees you paid to an MSSP, Pescatore says, youd need better lawyers than theirs.
Sarah D. Scalet.
From: Pipe Cleaners
Other stories by Sarah D. Scalet
mssp liability
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



