Should you outsource your antivirus/antispam systems?

TechRepublic

Most businesses—especially at the enterprise level—run their own antivirus and antispam (AV/AS) systems. Another option—outsourcing AV/AS efforts—is being looked at very closely. While there is disagreement between vendors and analysts on whether use of this approach has increased during the past few months, both groups agree that its attributes make it well positioned as the severity and complexity of the problems grow.

For the most part, this is a traditional buy vs. build decision: Does the company want to invest in equipment and personnel (and their training) and retain full control of one of the most important infrastructure elements it has? Or is saving money so vital that the company is willing to rely on an entity that could have a different agenda—or even go out of business?

One thing is a bit different, though. In most buy vs. build scenarios, the end product—if configured, installed, and administered correctly—provides about the same level of benefits to the end user. AV/AS outsourcers, however, each claim that their services—though based on the same underlying technology—are positioned so differently that they are fundamentally more effective.

Vendors say that the outsourcing trend is growing both in the number of companies under contract and the average size of those companies. "We continue to see very good engagement with companies of all sizes, Fortune 500 companies as well as small and midsize businesses," said Bill Fallon, vice president of marketing for MailWatch.

Scott Petry, vice president of products and engineering for Postini, agreed. He said that the allure of outsourcing actually increases as complexity—represented in the number of locations that e-mail servers are located in, and other factors—increases. "I think indications are that the outsourcing model is overcoming the in-house, do-it-yourself preconceptions at even the largest companies," he said.

There are several areas in which proponents claim that outsourced solutions are better than solutions installed and administered by internal IT staffs.

More intensive updating
Vendors say that a fundamental difference between outsourced and in-house techniques is the reactive quality of the latter compared to the proactive approach of the former. In-house antivirus techniques rely on updates from the vendors. This is a bad idea, outsourcers say, for three interrelated reasons. First, there is a significant time lapse between when a virus or spam variant is identified and when the definition is prepared and distributed. Customers' systems are vulnerable during this lag. Second, the practical reality is that there are too many viruses for updates to be prepared and distributed. Frequently, new viruses—which are often variants of older ones—go unaddressed for days. Third is human nature: Available updates and patches often go uninstalled.

Outsource companies operate in a different dynamic. The approach is to change the MX record of the e-mail address and have it delivered from the public Internet to their servers. Since all of the traffic goes through this central point, updated virus definitions and spam catching mechanisms can be implemented instantaneously and as often as necessary. And, since their business is stopping viruses and canning spam, it is unlikely that they will be subject to the inertia common in IT departments.

The ability to update more frequently should be seen, proponents say, within the larger framework of the fact that outsourcers specialise in AV and AS. The point is that crackers, spammers, and assorted other bad apples are very clever. Even if businesses were willing and financially able to pour money on the problem and willing to update as soon as the patch or fix was available, existing generic IT staff is at a disadvantage simply because they aren't experts.

This is a world of increasing complexity. MessageLabs CTO Mark Sunner said that the configuration of the recently resurgent SoBig virus shows a convergence of spam and viruses. "It is basically the cold reality that it is a virus that installs a Trojan component whose sole aim is to compromise a machine to make it a spam relay," he said. The idea is that an IT staff would be hard pressed to react to such a novel scenario before significant damage was done.

Overall traffic reduction
Many in-house antispam and antivirus software packages work at the desktop. Segregating the spam from the legitimate mail before it reaches the network—at the outsourcer's servers—can save tremendous network capacity in cases where the alternative is desktop-based.

IT support
The reality is that IT departments are stretched to the breaking point because of staff reductions and the increasing complexity of the tasks they are being called on to perform. AV/AS is the perfect element to outsource, service providers say.

Synergistic benefits
The fact that the outsource model introduces another server into the mix creates some interesting side benefits for customers. For instance, the outsourcing company can act as a load balancer between the client company's e-mail servers, as a redundant server in case of a problem, or even as a stand-in during scheduled maintenance.

Finally, outsourcers claim that they have a superior solution because they are in a position to run AV and AS software from more vendors simultaneously.

Neither Masha Khmartseva, a senior analyst with The Radicati Group, nor Michael Osterman, principal of Osterman Research, had serious qualms with the vendors' rationales.

"There are some really good propositions here," Khmartseva said. "It really lowers the cost. You don't have to pay a lot of money up front and you don't have to manage in house." She added that such an arrangement can make it easier to scale to larger groups of users.

Another factor is that it may make sense for IT to get out of the e-mail business altogether. Perhaps a decade ago not all companies had e-mail systems, Osterman said. Those companies that had e-mail enjoyed a competitive advantage and were disposed to treat it as a core IT element. Today, e-mail is a commodity service. "For a lot of organisations it pays to outsource e-mail messaging components so that they don't have to put IT staff into it," he said.

However, though they agree that outsourcing of AV/AS is well positioned, the analysts clearly don't feel that it is exploding. Khmartseva said that it seems to be growing, but only at the same rate as the overall AV/AS market, which, of course, is growing quickly. The analysts also don't see uptake among enterprises. Big companies are more inclined to not trust an outsider with such a mission-critical task.

TechRepublic is the online community and information resource for all IT professionals, from support staff to executives. We offer in-depth technical articles written for IT professionals by IT professionals. In addition to articles on everything from Windows to e-mail to firewalls, we offer IT industry analysis, downloads, management tips, discussion forums, and e-newsletters.

©2003 TechRepublic, Inc.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Refund for some Facebook investors http://t.co/tUUxRbJd

RT @zdnetaustralia: Is Windows Phone really the third challenger to Android and iOS? http://t.co/2V9xgN6d

Cloud inefficiency - Bad habits are hard to break | ZDNet http://t.co/j4pda3KC

30 servers to 7: BUPA redoes virtualisation http://t.co/EPL5pPpl via @zdnetaustralia

Refund for some Facebook investors http://t.co/TdKeV7y0

Research key to good apps: Westpac CIO http://t.co/tqHNyHs5

by http://t.co/vmlLt4bh: Refund for some Facebook investors: Morgan Stanley, the lead investment bank in Facebook... http://t.co/TZuND7bC

Refund for some Facebook investors: Morgan Stanley, the lead investment bank in Facebook's troubled initial publ... http://t.co/tmiz9zwu

Refund for some Facebook investors: Morgan Stanley, the lead investment bank in Facebook's troubled initial publ... http://t.co/g1t9N5Pb

IT Priorities: servers and storage http://t.co/E1U97jCk

RT @rladvisory: Video - Rob Livingstone @EVOLVECloud 'Getting cloud adoption right' - @zdnetaustralia http://t.co/G6GwvJCp http://t.co/nJrIY3vA @rladvisory

What's happening now with storage and servers? We delved into the area in our IT Priorities webinar series. http://t.co/XmLAsln8 ^ST

RT @rladvisory: ZDNet Video of my recent Executive Keynote presentation delivered at the EVOLVE.Cloud conference entitled...: http://t.co/2h9hEno2

IT Priorities: servers and storage: In November 2011, ZDNet Australia published the results of its IT Priorities... http://t.co/uOxpN90t

IT Priorities: servers and storage http://t.co/iQ6oT7qe

Accelerator targets 'clean-tech' start-ups http://t.co/8kGTxJGp via @zdnetaustralia

Westpac board goes paperless with iPads http://t.co/kdm26Ewr via @zdnetaustralia

Cloud TVRs stop in wake of TV Now ruling http://t.co/2hLRUvt6 via @zdnetaustralia

RT @WauloK: Two cloud-based TV recording services have been suspended after Optus TV Now. http://t.co/VomMRrRs // @techwebcast Beem is dead.

ZDNet Patch Monday ep137 - Removing the anonymity from Anonymous: http://t.co/E6Tn8vJr

ZDNet Patch Monday ep138 - Anonymous 'crippled': where to for hacktivism?: http://t.co/lbKew6Bo

ZDNet Patch Monday ep139 - War talk dominates AusCERT 2012: http://t.co/rUm22Zjm

ZDNet Patch Monday ep135 - iiNet wards off AFACT, but what next?: http://t.co/0xVdYm6i

ZDNet Patch Monday ep136 - Blackhole crimeware as a service here to stay: http://t.co/evnCUlsX

GoogleTV will revolutionize television once viewers understand it http://t.co/c4lEyb3a

Reading this article is like stepping back in time. If I was Paul Berryman I would hang my head in shame. How embarrassing!!! I can’t b...

1 hour ago by MikeSkoey on 30 servers to 7: BUPA redoes virtualisation

Phone cloning, maybe, but bill duplication? Tech-heads give verdict
http://t.co/aw5SNigN
#ozpolitics

The registration sticker provided a visual reminder to the driver to renew regardless of what happened to the renewal letter. The experie...

1 hour ago by dccharron on NSW ditches rego stickers for tech

"xfire: Why is telecommunications being treated different to roads, water and electricity?" Good question, my guess is AUS is far behind...

2 hours ago by ngoctranminh on Five pros and cons of the NBN

“@zdnetaustralia: Is Windows Phone really the third challenger to Android and iOS? http://t.co/Tr7ASra0 ”. It's different but fast and good

Can HP bounce back? http://t.co/TSlWjmrA

Thanks for the response Luke, Given that the quotes are accurate, then the person in charge of the Vic Health App needs to find another j...

2 hours ago by butterflyeffecs on Android fragmentation steers Vic Health

Social business in Australia http://t.co/aBuXFy40 . Australian businesses still laging behind with social business. Time to catch up!

Can Windows Phone bring a new challenge? #WindowsPhone http://t.co/m82nU7hK

Nice analogy. Another factor is whether you can find 50 people with powerful enough weapons. Minassian's argument is essentially that the...

2 hours ago by Mukimu on National Botnet Network coming: Earthwave

RT @digitaltasmania: @ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

@ZDNetAustralia #NBN's Tassie upgrade to cost $1.3m http://t.co/1nTbLUJv -Countdown begins for 1st Oppn. MP to misconstrue per unit cost

RT @mosfreshmedia: Start-up accelerator targets cleantech 'Atlassians, BigCommerce' via @zdnetaustralia http://t.co/oho3oQSK @atpinnovations @hamishhawthorn

Can #HP bounce back?: HP's move to cut 27,000 jobs, reinvest in research and development (R&D) and generally get... http://t.co/dlgAhwxb

Can HP bounce back? http://t.co/qLlHB5FV

It's nice to see Tas finally get some decent internet connectivity, for too long Tas has been stooged on decent internet connectivity but...

2 hours ago by Jingles on NBN's Tassie upgrade to cost $1.3 million

Who is Luke Hartsuyker? He must be the Apprentice FUDster. As PaulPC has already said regional consumers want, deserve and are entitled...

3 hours ago by dickster on Regional review highlights NBN, mobile

Its good to see the NBN keeping up with the latest equipement & letting the people benefit from it. After all thats why it was a trial, ...

3 hours ago by fibretech on NBN's Tassie upgrade to cost $1.3 million

Shadow Minister for Regional Communications Luke Hartsuyker has got it wrong. Regional consumers want improved mobile services AND the NB...

4 hours ago by PaulPC on Regional review highlights NBN, mobile

Just remember that Google haven't broken any laws here, they're just doing what all their other multinational competitiors do; minimise t...

4 hours ago by Pachanga on Much ado about Google's tax

ルイヴィトン バッグ : http://www.lovebagjp.com/ Louis Vuitton bags, Louis Vuitton pretension nose about,Louis Vuitton daydre...

5 hours ago by bundLourb on Reservoir blogs: Fan fakes Tarantino diary

シャネル バッグ : http://www.bagssalejp.org/ Chanel trap,chanel shekels,gucci bags,direct purse,poor recent Louis Vuitton keep...

7 hours ago by bybrinkLync on Reservoir blogs: Fan fakes Tarantino diary

I guess but in both cases, dead body!

16 hours ago by Doubt on National Botnet Network coming: Earthwave

I think it's for the very reasons you mention in your first paragraph that there is no CBA. With the ideological differences and vested ...

17 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

Good points; but how do you establish consensus about the terms of reference of a cost-benefit analysis? What is to be included? How far ...

17 hours ago by Gwyntaglaw on NBN cost-benefit analyses are so 2011

I live in a small country town & have done since 2002. When I got to this town it had no mobile phone & no broadband. The only reason w...

18 hours ago by fibretech on Regional review highlights NBN, mobile

Hi there, just became alert to your blog through Google, and found that it is really informative. I am going to watch out for brussels. I...

18 hours ago by Uttedsips on Fujitsu Stylistic ST5011

Like most things in life, the devil is in the details. If a cost benefit analysis included a societal element, I'm certain nobody on eit...

18 hours ago by RealismBias on NBN cost-benefit analyses are so 2011

The coalition has done nothing else but keep changing their view over the last 2 years. -first it was "there is nothing wrong with the ...

19 hours ago by djz on NBN cost-benefit analyses are so 2011

Use the force Luke... FFS

19 hours ago by Beta on Regional review highlights NBN, mobile

This story has been voted 12000 times in the last 24 hours!

22 hours ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar