Cybersecurity providers must first protect themselves

Issue 4 2023 Information Security

In a joint advisory released by cybersecurity agencies across the United States, UK, Australia, Canada and New Zealand, managed security service providers (MSSPs) have been warned of a sharp increase in cyberattacks targeting their systems. The agencies have identified MSSPs as a particularly lucrative target for malicious actors seeking to escalate their attacks and are urging the industry to take immediate action to address the threat.


Stephen Osler.

Stephen Osler, Co-Founder and Business Development Director at Nclose, warns that the cybersecurity industry must shed its naive mindset around the potential impact of supply chain attacks to effectively combat this growing trend.

“The way of thinking around security providers has evolved. In the past, these providers were primarily known as infrastructure providers, with a focus on providing IT services rather than security services,” he explains. “As a result, they weren’t that worried about making sure their own security was airtight.” However, with the increasing number of cyberattacks targeting security providers, the industry has realised the need to prioritise security. These attacks have trickled down into their clients’ ecosystems and infrastructure, making it crucial for providers to ensure they are secure.

When an MSSP is vulnerable, every one of their clients is vulnerable and this is a real threat. As the saying goes, ‘the plumber’s house always leaks’. “This cannot apply to cybersecurity. It is vitally important that cybersecurity service providers’ focus inwards to ensure that every one of their doors is bolted,” says Osler.

“Three years ago, Nclose embarked on a journey to become ISO 27001 certified. This is the world’s best-known standard for information security management systems (ISMS). We realised that we can’t give clients advice on how to secure their environments if we were not certified ourselves,” says Osler.

MSSPs need to establish in-house teams solely dedicated to ensuring their own security is top-notch, in the same way that they safeguard their clients’ systems. This means implementing the same rigorous controls, ensuring that all compliance expectations are met and that the organisation constantly undertakes penetration testing on themselves.

“The more the MSSP undertakes pen testing, vulnerability scanning, phishing tests and training, the more it will refine and polish its own security maturity,” says Osler. “Security companies have to ask themselves the same questions they would ask their clients and challenge their own internal employees and systems on a continuous basis. All testing should be done by a third party as they will be far less forgiving and be far more committed to finding the gaps.”

Wrapping security around every aspect of the business not only ensures that the MSSP is equipped to handle the challenging cybersecurity landscape more effectively, but that teams are quick to catch potential issues before they become gaping security chasms. This can make all the difference between an unexpected backdoor making a huge dent in a company’s reputation and future. Having teams ready to shut the door the moment it swings open is vital.

“It is as important for cybersecurity providers to be responsible and protect our own information as it is to protect our clients,” concludes Osler. “We have to evolve with the threats and that means more than just knowing what’s out there, it means knowing what’s inside the business and having all the right systems in place to ensure security is as comprehensive as possible.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The dangers of parked domains
Information Security
Kaspersky warns that fraudsters are exploiting so-called ‘parked domains’ to harvest sensitive personal data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.