Clear contracts are essential for secure operations

Last week’s cyberattack on the operations provider TietoEvry has shaken many players in the business community, as well as among municipalities and government agencies. Customers and suppliers, politicians and civil servants in large and small organisations alike — all share the same experience: operations grind to a complete or partial halt when the digital systems go down.
The parties directly affected are now restoring their IT systems while ordinary operations must run on temporary routines as best they can. How difficult, time-consuming and costly the work becomes depends on which security measures were in place before the attack (such as backups and backup systems), but also on whether there are disaster recovery plans to follow during the restoration.
Once regular operations are back up, customers may once again read through their operations and management agreements in general, and IT security agreements in particular, with their suppliers. Who is actually responsible for what? Our experience is that there are often gaps in how agreements are written and how they are applied. For example, it can be unclear which contracting party is responsible for what, and how the parties should act when something goes wrong and responsibility falls short.
An operations and management agreement must clearly document what is included in the commitment between customer and supplier, and the division of responsibility between the parties. Responsibility can be shared between the parties, meaning that one party is responsible for carrying out a measure while the other party bears the cost of the measure. An agreement should also state whether there are conditions that must be met for agreed service levels to apply, as well as how service levels are measured and followed up.
A simple example is when an IT system becomes vulnerable because an application in use is an older version and stops working if the operating system is updated with new patches. The agreement should clearly state:
- Who is responsible for handling incidents and problems resulting from the operating system not being updateable.
- Who bears the cost of handling these incidents and problems.
- How the application’s availability is measured.
- When the application must be available.
- Whether the operating system must be up to date for the agreed service levels to apply.
An operations and management agreement can be supplemented with general terms and conditions on IT security and an agreed continuity plan with preparedness measures. The customer and the supplier need to work together to identify and minimise risks, and to plan how operations will be conducted and restored in the event of a major crisis or disaster.
It cannot be emphasised enough how important it is to test your recovery plans — to have actually carried out, recently, a restoration from backups and the establishment of alternative operating environments. That reveals what remains to be addressed in order to build resilience.
Seclight is a consultancy firm focused on digital security.
Contact: David Hässler, telephone 08-94 55 99 david.hassler@seclight.com


