Examples of different CSaaS types
| Service | Description | Examples of services |
|---|---|---|
| Security personnel | Contracting out services associated with specific roles, either strategic or more operational/technical | Chief Information Security Officer (CISO) (including so-called virtual CISO), forensics specialist, pentester |
| Cybersecurity training | Training programs and courses intended to raise cyber-awareness within organizations and/or limit the impact of data breaches | Webinars, workshops, phishing campaigns, regulatory compliance training, desktop exercises |
| Vulnerability assessment | Systematic identification, measurement, and categorization of weaknesses within an organization's systems | “Patching” requirements, corporate security policies, remote access |
| Periodic penetration testing | Simulated attacks, performed by highly skilled personnel, with a view to ‘stress-test’ an organization's IT systems and find vulnerabilities before exploitation | Penetration testing |
| E-mail security | Services aimed at protecting corporate email accounts, one of the biggest gateways to organizations | Spam filters, digital signatures, email encryption |
| Identity and Access Management | Mapping and protection of corporate identities and accounts, to prevent take-over and malicious usage | User registration, assignment of roles and privileges, Multi-Factor Authentication (MFA) |
| Cyber-insurance | One of the most outsourced security functions, it entails sharing the financial impact of cybersecurity risks with a third-party provider | – |
| Incident response | The ability to rely (often 24/7) on third-party providers who intervene ‘boots-on-the-ground' to assist in case of a data breach | Security Operations Centre, cyber-crisis team |
| Business continuity and disaster recovery planning | Longer-term interventions aimed at bringing the organization to the pre-event stage | Recovery plans |
| Security information and event management (SIEM) | Detection and investigation of events to identify genuine threats and distinguish them from false positives | Security Operations Centre, SIEM platforms |
| Patching and updates | Upon disclosure of system vulnerabilities, remediation is performed through application of patches and updates | Software and configuration updates, operating systems patching |
| Compliance with security standards | Often outsourced to consultants with expertise in the governance, risk and compliance space (GRC), these services aim at aligning the organization with cybersecurity best practices | ISO/IEC 27001, NIST Cybersecurity Framework |
| Service | Description | Examples of services |
|---|---|---|
| Security personnel | Contracting out services associated with specific roles, either strategic or more operational/technical | Chief Information Security Officer (CISO) (including so-called virtual CISO), forensics specialist, pentester |
| Cybersecurity training | Training programs and courses intended to raise cyber-awareness within organizations and/or limit the impact of data breaches | Webinars, workshops, phishing campaigns, regulatory compliance training, desktop exercises |
| Vulnerability assessment | Systematic identification, measurement, and categorization of weaknesses within an organization's systems | “Patching” requirements, corporate security policies, remote access |
| Periodic penetration testing | Simulated attacks, performed by highly skilled personnel, with a view to ‘stress-test’ an organization's IT systems and find vulnerabilities before exploitation | Penetration testing |
| E-mail security | Services aimed at protecting corporate email accounts, one of the biggest gateways to organizations | Spam filters, digital signatures, email encryption |
| Identity and Access Management | Mapping and protection of corporate identities and accounts, to prevent take-over and malicious usage | User registration, assignment of roles and privileges, Multi-Factor Authentication (MFA) |
| Cyber-insurance | One of the most outsourced security functions, it entails sharing the financial impact of cybersecurity risks with a third-party provider | – |
| Incident response | The ability to rely (often 24/7) on third-party providers who intervene ‘boots-on-the-ground' to assist in case of a data breach | Security Operations Centre, cyber-crisis team |
| Business continuity and disaster recovery planning | Longer-term interventions aimed at bringing the organization to the pre-event stage | Recovery plans |
| Security information and event management (SIEM) | Detection and investigation of events to identify genuine threats and distinguish them from false positives | Security Operations Centre, SIEM platforms |
| Patching and updates | Upon disclosure of system vulnerabilities, remediation is performed through application of patches and updates | Software and configuration updates, operating systems patching |
| Compliance with security standards | Often outsourced to consultants with expertise in the governance, risk and compliance space (GRC), these services aim at aligning the organization with cybersecurity best practices | ISO/IEC 27001, NIST Cybersecurity Framework |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.