Why European businesses are partnering with MSSPs to improve IT security

Hand hovering over laptop with padlock graphic superimposed

In the face of WannaCry, NotPetya and numerous other high-profile data breaches, European businesses are seriously re-evaluating how they manage their cybersecurity. They are looking for solutions that succeed in safeguarding critical data, but also serve all their other business and IT needs. There are still barriers to overcome and buyers will need to to be convinced if they are to part with cash for that initial managed security services provider (MSSP) adoption.

Rising cybercrime, digital disruption and increased compliance demands are threatening the stability of businesses across Europe. Dealing with cybercrime alone is a challenge, but as businesses look for a competitive edge through digitisation, and with the General Data Protection Regulation (GDPR) just over the horizon, many are looking for outside help.

Increasingly, that help comes in the form of an MSSP. For some areas of an organisation, particularly in the UK where outsourcing has long been practiced, it might come as a surprise that MSSPs are still seen as a relatively new concept and one that's still treated with suspicion by security chiefs. The issues are trust and control -- handing over the security keys of a business is not something to be taken lightly.

However, there has been a clear growth in MSSP adoption across Europe as the triple pressures of cybercrime, skills shortages and compliance begin to take their toll on under-pressure IT departments and boardrooms fret about the business impact of data breaches. So outside help is being sought, but that doesn't mean that any MSSP is going to get an easy ride.

Recent Reliance acsn research highlighted that 66% of European businesses are already using an MSSP, with a further 24% planning to invest. The remaining 10% are in the process of evaluating the prospect. This demonstrates that across the board industry sectors are putting aside their reservations about using an outsourced security service. That said, the results within the sectors show that there's still some reluctance to accept the idea of fully outsourced security.

We can see that the idea of outsource is catching on, but there is still some way to go before end users completely trust an MSSP to manage security. As a result, 53% are at an early stage of planning, with only 12% at an advanced stage.

The results show the trends they are most concerned about also tend to be the drivers of change and innovation across European businesses, and confirm the feeling that the better things get in terms of digital transformation, the worse they get for security. Mobile (74%), cloud (67%) and IoT (58%) were the most frequently mentioned concerns in our report, while other major IT trends such as digital transformation (50%) and shadow IT (34%) were also frequently mentioned. These results give a reflection of what end users are thinking about and dealing with right now.

Client organisations have a mixed view of the benefits that an MSSP can provide, and different parts of the organisation have different expectations. The board looks initially to save money, whereas security teams look for help and technology that they cannot deliver in-house. An MSSP is not for life, or even for a whole organisation. Businesses are taking a pick-and-mix approach, and even taking some functions back in-house. In an age of pay-as-you go cloud and SaaS, MSSPs need to be flexible in terms of outlook and delivery, and agile enough in the face of frequent policy changes and new threats.

Michael Clifford is the managing director at Reliance acsn

Latest in Security
Ransomware concept image showing a warning symbol in red with binary code in background.
Healthcare systems are rife with exploits — and ransomware gangs have noticed
Application security concept image showing a digitized padlock placed upon a digital platform.
ESET looks to ‘empower’ partners with cybersecurity portfolio updates
NHS logo displayed on a smartphone screen in white lettering on a blue background.
NHS supplier hit with £3m fine for security failings that led to attack
OpenAI logo and branding pictured at Mobile World Congress 2024 in Barcelona, Spain.
OpenAI announces five-fold increase in bug bounty reward
Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.
These five countries recorded the most third-party data breaches last year
Phishing concept image showing an email symbol with fishing hook.
Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack
Latest in Feature
A photo of UNSW's Sunswift 7 car pictured in front of Uluru in Australia's Northern Territory.
How UNSW’s Sunswift Racing and Ericsson achieved cross-country connectivity in Australia’s outback
Matt Clifford speaking at Treasury Connect conference in 2023
Who is Matt Clifford?
Open source vulnerabilities concept image showing HTML code on a computer screen.
Open source risks threaten all business users – it’s clear we must get a better understanding of open source software
An abstract CGI image of a large green cuboid being broken in half with yellow, orange, and red cubes to represent ransomware resilience and data encryption.
Building ransomware resilience to avoid paying out
The words "How effective are AI agents?" set against a dark blue background bearing the silhouettes of flowchart rectangles and diamonds to represent the computation and decisions made by AI agents. The words "AI agents" are yellow, while the others are white. The ITPro Podcast logo is in the bottom right-hand corner.
How effective are AI agents?
An illustration showing a mouth with speech bubbles and question marks and a stylized robot alien representing an AI assistant chirping away with symbols and ticks, to represent user annoyance with AI assistants.
On-device AI assistants are meant to be helpful – why do I find them so annoying?