Lacking a cybersecurity plan is costing you clients

August 14, 2015  |  Startland News Staff

MINOLTA DIGITAL CAMERA

Apprameya Iyengar is a technology and securities attorney with Polsinelli PC. His work focuses on commercial technology needs, ranging from small and mid-cap emerging companies to Fortune 500 companies.

For technology startups, maintaining strong security controls remains vital to winning new business opportunities and strengthening existing relationships.

Appi

Apprameya Iyengar

Despite the global spike in cybersecurity attacks — there were 42.8 million detected cybersecurity attacks in 2014 — big companies continue leveraging technology startup vendors to help perform critical business functions containing access to personally identifiable information (PII), protected health information (PHI), and personal financial information (PFI).

However, larger enterprises are conducting more due diligence than ever before at the outset of their procurement process, evaluating their technology vendor’s security policies and procedures and assessing the service provider’s ability to remain resilient and recover data in the event of a security breach.

Increasingly, sophisticated cybercriminals are infiltrating smaller technology providers as outlets to exploit PII, PHI, and PFI, and using such attacks to steal valuable intellectual property and disrupt critical business processes. Surprisingly, many technology startups lag behind their more mature counterparts in implementing and maintaining effective controls against common cybersecurity risks. In response, larger enterprises are prioritizing how they manage their global cybersecurity exposure, especially when engaging startup vendors.

Technology startups planning to target large businesses should invest the time and effort to create and maintain a documented and well-organized set of information security protocols.

What policies and procedures do big companies expect their technology startup vendors to implement and maintain?

Many large enterprises expect technology startup vendors to maintain a well-documented information security program, overseen by a designated company officer, which, at a minimum, directly addresses:

What security controls are in place to protect the customer’s data?

Has the vendor instituted encrypted perimeter and network security measures to keep out and/or detect intruders?

How often are security updates provided by the vendor?

How often are these procedures audited for effectiveness (e.g., SSAE-16)?

Where will the customer’s data be stored?

Depending on how the technology is being delivered (e.g., cloud, ASP, or on-premise), will customer data be stored on-site or offsite?

Will any customer data be stored or transferred abroad?

How quickly and by what means will the service provider detect unauthorized intrusions and, if there is a security incident or a data breach, what are the vendor’s response and notification protocols? Early incident detection, rapid security restoration, and a swift triage of the situation are critical. A large company will need to mobilize instantly when faced with a security incident or data breach, and a clearly articulated incident response plan will be viewed favorably.

Cybersecurity and privacy liability insurance, covering any unauthorized access to and use of the customer’s data, breach notification costs, and costs to defend regulatory actions involving a data breach are expected, with sufficient coverage amounts depending on the type of data involved.

Larger enterprises are evaluating their prospective technology startup vendors on their security capabilities more than ever before. Technology startups can distinguish themselves as responsible business partners and win more business opportunities by maintaining effective safeguards against cybersecurity risks that pose serious threats to businesses of all types.

startland-tip-jar

TIP JAR

Did you enjoy this post? Show your support by becoming a member or buying us a coffee.

Tagged , , , ,
Featured Business
    Featured Founder

      2015 Startups to Watch

        stats here

        Related Posts on Startland News

        Letter to KCMO City Council from the entrepreneur, small biz community (via Eze Redwood)

        By Tommy Felts | March 15, 2022

        Editor’s note: The following letter was sent to Kansas City, Missouri, city council members March 11 by serial entrepreneur Eze Redwood, advocating for $11 million in funding for entrepreneur support from KCMO in its 2022-2023 budget. The city council is set to vote on the budget by March 24. The opinions expressed in this commentary…

        Kharissa Forte, Holistic Hustle, Grace & Grind

        We all need help, honey: Nearly 3/4 of entrepreneurs are haunted by depression (Holistic Hustle)

        By Tommy Felts | March 8, 2022

        Kharissa Forte is a writer, certified health coach, and columnist for Startland News. For more of her self-care tips on how to keep your cup full, visit graceandgrind.co. You did it. After all the nights dreaming about how amazing it could be and overcoming the endless stream of what-ifs that stopped you from moving forward…

        Bo Fishback, Airtasker

        KC workers aren’t leaving — they just want more control over their jobs; Why that isn’t such a weird flex

        By Tommy Felts | February 14, 2022

        Editor’s note: The opinions expressed in this commentary are the author’s alone. Bo Fishback, CEO of Airtasker USA, a local services marketplace that connects people who need work done with those who are ready to work, previously founded Kansas City-based Zaarly. The startup was acquired by Airtasker in 2021. Corporate America’s “Great Resignation” is largely…

        Kharissa Forte, Holistic Hustle, Grace & Grind

        Faking it ’til you make it might be why you have imposter syndrome (Holistic Hustle)

        By Tommy Felts | February 8, 2022

        Kharissa Forte is a writer, certified health coach, and columnist for Startland News. For more of her self-care tips on how to keep your cup full, visit graceandgrind.co. I’m not one to get caught up in the hoop-lah of celebrity crushes, but if there’s anyone who I #WCW it’s my Pisces twin Rihanna. (I mean,…