Table 1

Examples of different CSaaS types

ServiceDescriptionExamples of services
Security personnelContracting out services associated with specific roles, either strategic or more operational/technicalChief Information Security Officer (CISO) (including so-called virtual CISO), forensics specialist, pentester
Cybersecurity trainingTraining programs and courses intended to raise cyber-awareness within organizations and/or limit the impact of data breachesWebinars, workshops, phishing campaigns, regulatory compliance training, desktop exercises
Vulnerability assessmentSystematic identification, measurement, and categorization of weaknesses within an organization's systems“Patching” requirements, corporate security policies, remote access
Periodic penetration testingSimulated attacks, performed by highly skilled personnel, with a view to ‘stress-test’ an organization's IT systems and find vulnerabilities before exploitationPenetration testing
E-mail securityServices aimed at protecting corporate email accounts, one of the biggest gateways to organizationsSpam filters, digital signatures, email encryption
Identity and Access ManagementMapping and protection of corporate identities and accounts, to prevent take-over and malicious usageUser registration, assignment of roles and privileges, Multi-Factor Authentication (MFA)
Cyber-insuranceOne of the most outsourced security functions, it entails sharing the financial impact of cybersecurity risks with a third-party provider
Incident responseThe ability to rely (often 24/7) on third-party providers who intervene ‘boots-on-the-ground' to assist in case of a data breachSecurity Operations Centre, cyber-crisis team
Business continuity and disaster recovery planningLonger-term interventions aimed at bringing the organization to the pre-event stageRecovery plans
Security information and event management (SIEM)Detection and investigation of events to identify genuine threats and distinguish them from false positivesSecurity Operations Centre, SIEM platforms
Patching and updatesUpon disclosure of system vulnerabilities, remediation is performed through application of patches and updatesSoftware and configuration updates, operating systems patching
Compliance with security standardsOften outsourced to consultants with expertise in the governance, risk and compliance space (GRC), these services aim at aligning the organization with cybersecurity best practicesISO/IEC 27001, NIST Cybersecurity Framework
Source(s): Authors’ own work

or Create an Account

Close Modal
Close Modal