1 / 2100%
I believe the biggest risk to outsourcing information system functions
is the diverse clientele these companies have. A company that
provides outsourcing capabilities can have many clients, which allows
them to offer their services cheaper. My concern with this is the
different requirements clients will have for the outsourcing company
and how that company can reasonably provide secure information
system services and connections for all. In addition, should a breach
happen at the outsourcing business, it is very likely all businesses they
are providing the services to will be affected. "Outsourcing is a much
more intricate investment than just using an outsourced company. It
also implies more significant attention to the contracted companies.
There are concerns with service delivery, support, consulting,
planning, project execution and the appropriate handling of sensitive
data" (Rodrigues, 2022). It is difficult for a company to control the
contracted outsourcing company, especially if offshore. Concerns
could arise about how that outsourcing provider is handling the
information and to what standards they operate versus what the
client is demanding. One example of an outsourcing firm being
hacked is WiPro in India. The company offered IT outsourcing for
many businesses and most if not all businesses were affected by the
attack. "After the attackers gained access to more than 100 WiPro
computer systems through dozens of employee accounts, they were
able to install remote access tools on the compromised systems"
(Valeo Networks, 2022).
The organization has the duty to ensure the security of customer data
when that customers entrusts the information to them. The
organization should create and include policies in their contracts with
outsourcing providers that ensure customer data is protected during
all eventualities. Proper penetration testing should be performed at
regular intervals and should be required by contract. If the
outsourcing firm has multiple businesses as clients, that data should
be properly separated by separating the internal networks to ensure
minimal damages. All policies to minimize risk should be overseen by
the organization entrusting their customer data to outsourcing
businesses. A data breach can have extremely damaging
consequences to the organization and all involved. The damages can
be monetary and reputation based, potentially causing the
organization to shut down. Therefore, not only does the organization
carry an ethical responsibility to secure customer data, it carries a
fiscal responsibility as well.
References:
Rodrigues, Mateus H. (July 12, 2022). The Influence Of Data
Protection Laws On Outsourcing Software Development Projects.
Retrieved from
https://www.forbes.com/sites/forbestechcouncil/2022/07/12/the-
influence-of-data-protection-laws-on-outsourcing-software-
development-projects/?sh=4b9adc9542dd
Valeo Networks. (2022). THIRD-PARTY DATA BREACHES — WHAT
TO CONSIDER WHEN OUTSOURCING IT. Retrieved from
https://www.valeonetworks.com/third-party-data-breaches-what-
to-consider-when-outsourcing-it/
Students also viewed