Last night was more than just trash night in the Black household. It was also the night of, “Rob, the cleaning lady is coming tomorrow.”
Which meant, as it does every other Wednesday night, that I had to clean for the cleaning lady.
Okay, “clean” is not quite the right word. What I needed to do was get my stuff out of the way…
Take my things off the night stand … put away the folding chairs that have been sitting out all week … move that box of Savers donations into my car … etc., etc.
Because – and I’m embarrassed to admit how many years it took me to understand – if I don’t do my job, she can’t do hers.
A cleaning lady who comes across two folding chairs parked in the middle of the room doesn’t clean the entire room – she cleans around the chairs. The floor beneath stays dirty.
This is not a criticism … it’s a question of scope. Hers extends only as far as what can be cleaned without moving things around. That’s my job.
And so every other Wednesday evening, when Mrs. Black issues her standard reminder, I get to work.
As it turns out, and whether you realize it or not, this same “clean what can be seen” approach is exactly how most of your vendors operate. They work with what you give them – the rest is up to you.
“We Hired the Experts, So We’re All Set”
The most expensive assumption I encounter in my discussions with clients, colleagues, friends, and assorted business owners, is that hiring somebody makes the problem go away:
The MSP manages our endpoints, so endpoints are handled.
The SOC watches our alerts, so alerts are handled.
The compliance platform dashboard is 94% green, so compliance is handled.
Except, no.
Your vendors do the cleaning. But there are decisions made by you and your team (some explicitly, some by default) that determine how and what that consists of.
Clear Lines Are Needed
In the physical world, the concept of “shared responsibility” – the line between what the vendor does and what the customer does – is well understood.
When you hire a security company to alarm your house, it’s up to them to make sure everything functions as it should.
But they don’t lock your front door when you leave, and they don’t arm the alarm when you go to bed at night. That’s your job.
In the world of cybersecurity and data management more broadly, many companies behave as if the notion of shared responsibility doesn’t exist.
Three Jobs Nobody Can Do For You
#1. Deciding what you have – and what you keep.
Your MSP can inventory and track the devices it manages. Terrific.
But it can’t tell you that your marketing team is running three SaaS tools on somebody’s personal credit card, because nobody told your MSP those tools even exist.
Likewise, no vendor is going to walk in and tell you to stop storing customer records from 2014, resumes from candidates you didn’t hire six years ago, or a spreadsheet of employee bank details from a payroll migration that finished during the Obama administration.
The vendor can lock down a room. You are the one who decides what goes in that room and what, at this point in time, should be tossed.
#2. Deciding who’s in charge of what.
Any provider will happily create the accounts and associated permissions you request. That’s the service.
But they are not going to show up at your staff meeting and ask why 11 of your 40 employees have global admin permissions. Or why the sales manager who moved on six months ago is still listed in your directory and still retains access to everything she had while still on the payroll.
Access looks like a technical issue. It’s not; it’s a business decision. Somebody at your company – a name, not a job title – has to own it.
#3. Deciding how much risk you can live with.
A good vendor will tell you what your risks are. A great vendor will tell you what it would take to reduce those risks and what it would cost if something went wrong.
But no vendor will tell you which risks are worth carrying and to what degree – that’s up to you.
How much downtime can your business absorb before customers start leaving?
Which contract has the breach-notification clause that turns a bad week into a lawsuit?
What loss would be survivable, and what loss would be the end?
Those answers don’t live in a vendor dashboard. They live in your margins, your contracts, your board, and your gut.
When Things Go Horribly Wrong
The pattern is remarkably consistent.
Something bad happens. Everyone turns to the vendor and asks how this got through.
The vendor calmly pulls up the scope of work – which covers exactly what it always covered – and, more often than not, the recommendation email it sent long ago that nobody on your team ever replied to.
The vendor isn’t at fault – they did exactly what they promised to do. But until now, you assumed that meant “taking care of everything.”
Put Your Stuff Away
You don’t need a project plan for this. You need about an hour, this week:
- Understand your vendor’s scope. Meet with them to explicitly discuss who is responsible for which pieces. Look for the gaps.
- Name owners, not departments. “IT owns access reviews,” is not ownership. “Dana runs the access review the first week of every quarter,” is.
- Find the open recommendations. Every provider you have has told you to do something you haven’t yet done. Collect those items into one list and decide – out loud, on purpose – which things you will do in what order, and which things you’re going to live with.
Accepting a risk knowingly is a legitimate business decision. Accepting it because you assumed somebody else had it taken care of is just rolling the dice.
Gotta run. Those chairs don’t move themselves!
Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!