Worm out of virus management



Antivirus management is complex, time consuming, and absolutely essential. Handing it over to a service provider could prove to be the easiest--and safest--option.

The rules of virus management have changed dramatically during the past three years. Even enterprises with a great deal of internal security expertise and generous budgets to tackle the problem have found it hard to protect themselves from an onslaught of virus threats.

Viruses and malicious-code programs are now more frequent and effective in their mission. Malicious-code programs are infecting the enterprise at an unprecedented, rapid-fire rate--often before the antivirus vendor can create an update or before the enterprise can distribute the update to its Simple Mail Transfer Protocol (SMTP) gateway and desktops. Moreover, most small and medium businesses (SMBs) don’t have the resources of larger enterprises to institute 24x7 internal testing and distribution of new updates.

The means of virus infection is also changing. E-mail systems remain the most dominant method by which enterprises are infected. However, as Nimda and Code Red demonstrated--and as instant messaging vulnerabilities and the advent of Web services portend--Web servers, Web applications, and active content eventually will have to be protected from malicious-code attacks.

The already-strained method of signature-based detection used on desktops, file servers, and at the Internet gateway will not suffice for these newer threats. However, through 2003, e-mail will remain the primary vector for malicious-code infections for most companies.

The antivirus campaign
To keep your company safe from future virus attacks you will need a good antivirus program in place. Buying and installing the appropriate software is not the total solution, instead it is just the beginning. Effective protection comes from the management of the software.

And of course antivirus software should not be your total solution, there are also firewalls to consider, as well as intrusion detection systems and many other security solutions on offer; antivirus software is just one part of an overall security strategy-- albeit an important and time-consuming part.

The amount of time you should invest in managing your antivirus software will vary from company to company--depending on the size of the organisation, whether you are protecting from the gateway or desktop, or both, and how much of a priority you place on antivirus systems. While some IT managers may spend 10 minutes a week on antivirus management, others will spend two hours a day.

If you are spending more time than you care to admit managing your company’s antivirus protection solution, or if perhaps the security space is getting too complex to handle, outsourcing is an option you shouldn’t overlook.

Consider outsourcing


Managed antivirus services (eg, My ASAP from McAfee), messaging service providers (eg, MessageLabs), and managed security service providers are all sources for antivirus protection. These service providers will remotely manage antivirus products on desktops, file servers, and, most commonly, the SMTP gateway and firewall. If you are lacking the resources to manage the constant updating of antivirus signatures and the frequent upgrading of antivirus product versions, managed antivirus services could be your answer to more effective and efficient antivirus protection.

While antivirus software has been around for a while now, the managed hosting of antivirus solutions isn’t so mature, but it is a market on the rise. Andrew Grace, of antivirus and security software company Trend Micro, thinks it is the way of the future, going as far to say that in five years time the people who are still managing security inhouse will be the odd ones out.

The reasons to outsource the security functions of your business are much like the reasons to outsource any other parts of your business--such as receiving 24x7 protection, exposure to expert staff, cost savings, and more effective time management.

At Symantec, senior director worldwide planning and strategy, Kerrie Turner, is finding customers really appreciate the access to expertise. “Security professionals are hard to get on the market, all over the world—they are hard to get, hard to keep, and very expensive,” she says. “SMEs have IT managers wearing all different hats, customers look to us for expertise.”

These sentiments are shared by Zento’s CEO Arthur Argyropoulos. “It is hard to find people with the proper accreditations and it is hard to retain them,” he says. Zento is a managed service provider specialising in McAfee and Trend Micro antivirus solutions.

For SMEs the problem of finding experienced security staff is real, as they don’t have the company numbers nor the budget to entice the experts. This is just one reason why Network Associates sees the small to medium businesses as the key market for outsourcing security solutions.

“Managed antivirus is a great idea but it isn’t for everyone. Antivirus is not core to your business but it is a critical part,” says McIntyre. “The larger enterprises have very heavy investment in IT anyway, and it isn’t really what they are looking for from their outsourcing partner.”

If the price is right
Of course a large factor in the decision to outsource is the cost. Some things to keep in mind are the ongoing costs of antivirus management, the cost of skilled staff, as well as taking into consideration the potential costs of business downtime if a virus worms its way into your system.

McIntyre estimates that buying antivirus software only accounts for 20 percent of the total cost of the antivirus solution, with the other 80 percent being management of the software. “How do you quantify the cost of the software--exactly how long is a piece of string?” he says. “The real cost is the distraction, keeping it up to date.”

Like most security solutions, the cost benefit can’t be derived from how much you are spending, but how much you think the company brand or a day’s work is worth--both of which are in jeopardy if a harmful virus infects your system. Most vendors are loath to give a out a price estimate, saying it is different for each company. Also it would be rare for a company to implement an antivirus solution alone, instead the cost of antivirus would just be a part of the total security solution. However, to give you an idea of pricing, Zento says it has solutions starting at US$500 a month.

Evaluating antivirus vendors


When it comes to finding a managed service provider, you will be best off to first choose your preferred software vendor, as MSPs will specialise in a couple of packages but not all. For example, Zento offers Trend Micro and McAfee, with some customers using both, such as Trend Micro at the gateway and McAfee on desktop. Software vendors themselves may also have a managed and professional services side of the business, as does Symantec and Network Associates.

Trend Micro doesn't provide the services itself, but partners with Zento and Telstra to deliver the managed service. Whether you are looking for just the antivirus software or for the whole managed offering, the following criteria may help you find the right partner:

  • Product quality on a specific platform--eg, Windows 2000 or Lotus Notes.
  • Elements to consider include how often product patches are released for that product version, as well as performance/compatibility.
  • Management and distribution functionality within the antivirus solution--ie, what mechanisms are available for easy and automated updating of desktops and other systems. Also assess how the antivirus vendor makes available updates, especially in outbreak situations. For example, if the vendor provides updates only from its Web site, you may be unable to download the update because of high demand at the site. If no alternative method of obtaining an update exists, you should ask what highavailability solutions the antivirus vendor uses on its Web site and demand service levels for obtaining the update from the site in an outbreak situation.
  • Research and customer support and service--eg, how quickly does the antivirus vendor typically produce an update in an emergency situation? Are alert and virus intelligence services included, as well as customer support contacts (especially in outbreak situations)? The quality of the updates will be critical if you don't have the capability to test updates. Negotiate firm service level agreements to ensure quality updates.
  • Incident-response plan--name a manager as the virusalert and incident-response liaison to your antivirus vendors and solution providers, and outfit key enterprise and vendor contacts with pagers or other alert devices. Also ensure that as soon as the new update is available from the antivirus vendor, the SMTP gateway is updated immediately.

Whether you are a small business of three people or a large enterprise with 3000 people, the importance of having an effective antivirus solution in place cannot be underestimated. Without wanting to be a scaremonger, security vendors have all sorts of scary statistics on the amount and types of attacks, future threats and the cost to businesses. As the threats increase and become more complex, so too do preventative measures. It isn't enough to kill the virus when it arrives on your doorstep, now you have to make sure it doesn't even get a look in. If your business doesn't have the time to devote to finding new solutions and posting software upgrades, outsourcing may be just the answer you are looking for.

Who's out there
Following is a guide to the providers that we spoke to for this article. This list is by no means exhaustive, there are many service providers who specialise in the security space and the large outsources such as CSC and EDS will also provide security services as part of their offering. Also remember that security service providers will usually offer more than just an antivirus solution.

McAfee
McAfee, with its ASaP managed services, offers three different packages for antivirus management. VirusScan ASaP is suitable for any sized business and is a simple antivirus manager, Virus-Screen is a service which scans emails for viruses and either cleans or quarantines infected messages, and lastly, Managed Virus Defense ASaP is the more advanced version of VirusScan ASaP, adding protection for the file server, groupware server, and gateway. McAfee also offers vulnerability assessment and firewall management.
www.mcafeeb2b.com

Symantec
Symantec is on its way to being a one-stop shop for security services, offering software, and both professional and managed services. It provides solutions for antivirus, firewalls, intrustion detection systems, virtual private networks, as well as vulnerability assessments and Internet content and email filtering.
www.symantec.com.au

Trend Micro
Trend Micro is one of the leading antivirus software vendors in Australia. It offers managed services through its partners Telstra and Zento--see information on Zento below.
www.trendmicro.com.au

Zento
Managed security service provider Zento offers managed services for antivirus, intrustion detection systems, and firewallsââ,¬"specialising in Trend Micro and McAfee products. Antivirus management services start from $500 a month.
www.zento.com.au

Subscribe now to Australian Technology & Business magazine.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

NBN users opt for 100Mbps - ZDNet Australia http://t.co/fLfHMzPn #australia #technews

RT @konradski: Whaddayaknow - turns out Wi-Fi CAN interfere with a plane's navigation systems http://t.co/ospQCU2S

This story has been voted 5 times in the last 24 hours!

1 hour ago, NBN's Tassie upgrade to cost $1.3 million

Sorry no deal Cinders, I'd rather send my money to someone and watch them desperately try to stop the NBN as this has much better enterta...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

What else can you expect from a Dodo customer?

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

NBN users opt for 100Mbps - Communications - News - ZDNet Australia: NBN users opt for 100Mbps - Communications ... http://t.co/btB9gKWg

NBN users opt for 100Mbps http://t.co/xKqEb4bE via @zdnetaustralia

Biometric bugs too dangerous for public? http://t.co/8JLz5tdF via @zdnetaustralia

Oh please dont be unkind, I gotta have some fan's. btw I agree I dont set the standard, but who does I wonder?

3 hours ago by Doubt on NBN users opt for 100Mbps

You agree but give him thumbs down... I think you'd better take the medication before one of your alter ego's Fred/Frank/Frergers appear...

3 hours ago by Beta on NBN users opt for 100Mbps

Exploring: http://t.co/rT7RPZLA

+1

4 hours ago by Beta on NBN users opt for 100Mbps

War talk dominates #AusCERT 2012 - http://t.co/SlBpMj0c - #security #cyber

So we agree it was a stupid idea and even stupider comment then ;-)

4 hours ago by Beta on NBN users opt for 100Mbps

Not you obviously ;-)

And stop giving yourself thumbs up FFS.

4 hours ago by Beta on NBN users opt for 100Mbps

Ok Beta, understand now, just one point who sets the standard?

4 hours ago by Doubt on NBN users opt for 100Mbps

Oh no Beta you misunderstand me. I like my waterfront home and deep water jetty, it's those "other" people who can move to Willunga.

4 hours ago by Doubt on NBN users opt for 100Mbps

I agree with you Magnus, but really most people like living on the coastal fringe.

4 hours ago by Doubt on NBN users opt for 100Mbps

Travel Tech Q&A: Skyscanner's Ewan Gray http://t.co/vYexrDwu #ipad

Exploring: http://t.co/YNVjdrct

Exploring: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia ... http://t.co/bNLCyobv #ICTChallenge

Exploring: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia ... http://t.co/HEPuJgyt #ICTChallenge

#NewSouthWales ditches registration stickers 4 light #vehicles in favour of #technology http://t.co/xX5N0Rp9

Another use is city based top surgeons using 8K resolution monitors to provide real-time assistance to country surgeons and doctors to op...

4 hours ago by Magnus on NBN users opt for 100Mbps

In terms of capacity, fibre is basically future proof. Never mind 100Mbps or even 1Gbps. Computer scientists have already achieved 100 gi...

4 hours ago by Magnus on NBN users opt for 100Mbps

What I like about Mike Quigley is that he is making it happen, despite all the bull**t barriers being put in front of him by Coalition po...

5 hours ago by Magnus on NBN users opt for 100Mbps

Anonymous hacks Reliance's Internet filtering server - ZDNet (blog) http://t.co/uObU1HBP http://t.co/0UBXxwX4

Which Windows will make for a better tablet? http://t.co/4mAHg850

Gonna be crowded when TA switches of the inter webby thingy and everyone moves there, just as you suggested though.

6 hours ago by Beta on NBN users opt for 100Mbps

Yes "without secure internet identification methods" I cannot see a future for online voting be it a referendum or selecting a Gov (at ...

7 hours ago by Taskmanager on A farewell to democracy: Kaspersky

Oh of course you would would want something in return. hmmm I see, well maybe my best wishes for and your family. btw, Western Union is ...

7 hours ago by Doubt on NBN users opt for 100Mbps

Well Willunga looks like a nice place to live, close to wine growing areas, a golf club. Houses are probably reasonably priced. Very nice...

7 hours ago by Doubt on NBN users opt for 100Mbps

Listening to @stilgherrian cover AusCERT and cyberwar, http://t.co/6lGUEz8H

http://edfarmaciaes.com/#0500 generico viagra barcelona EdFarmaciaEs sildenafil y sulfatos

7 hours ago by buy priligy cheap on Top alternatives to Microsoft Outlook

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/VN5tGJzC

#Westpac Board goes paperless with #Ipads with #Tabula #App http://t.co/duxuj2fd #Cybersecurity #Bank

Microsoft is serious about open source??? http://t.co/mqQGgta7

If I give you money what do I get in return? Do you know how commerce works or are you just a filthy poor that wants my monies for nothin...

8 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

@joedamato just try varying caps randomly. Maybe they do this http://t.co/1FN5FwYv

NSW outlines datacentre migration plans - Hardware - News - ZDNet Australia http://t.co/OQfUl0D1

MikeSkoey - thanks for your comments. Rather than hang my head in shame, I am proud of my achievements, particularly of being able to ru...

8 hours ago by Paul_Berryman on 30 servers to 7: BUPA redoes virtualisation

"on the new fast Internets everyone wants the fast plan" #orly #nareally #yarly http://t.co/kvfCa84A

Chrome overtakes IE: does it matter? http://t.co/e4SILk8a

A ZDNet study showed that British Facebook users are drunk in 76 percent of their photos.

The HDMI cable ripoff and why retail is really dying http://t.co/eFT7zEW7

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/IUysbyKf

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/V7vL5QB9

ZDNet reports Microsoft launches its own social service http://t.co/VJS5BkwF

by http://t.co/vmlLt4bh: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia P... http://t.co/4bfDRXo4

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/CtNlVWN7

Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia Pacific, shares some of h... http://t.co/ZxjpmqiM

Microsoft is serious about open source: 10 proof points http://t.co/iv2ji74q

Accelerator targets 'clean-tech' start-ups http://t.co/p9VPCzCa

RT @vexnews: NBN users opt for highest speed plan http://t.co/8eUvvVvQ

OutsourcingLive: #Outsourcing is still on the rise http://t.co/5U6R431A ^NK http://t.co/B8HtVvAD

This story has been voted 12000 times in the last 24 hours!

2 days ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar