Security Policy Management and MSSPs

For smaller companies that do not want to hire IT people to manage IT infrastructure, the best option is to work with IT service companies. As to security related needs there are MSSP companies all around the world and they are managing all kind of security equipment on behalf of their customers. The time required to maintain a security infrastructure or the operational activities in security infrastructures especially on firewall devices is a bit high. For repeatitive activities like firewall policy change activity that is going on in security policy management, the automation is a must due to several reasons. One of the reasons of policy change automation is the need for higher number of people handling of these manual operations. When there are new customers getting on board, the workload surely be increasing. So, to compensate this workload MSSP will hire new people if the capacity is not enough. Assuming five security operation engineer is a need to give service to around 20 customers. When the number of costomers reach to 100, to be able to give a good level of service, 25 employees be needed. It will be scale and budget issue and must be handled in a different way because as the number of customers increasing there must be a way of reducing this capacity need to make a profitable business. Apart from higher employee need as the number of customers increase, finding employee is a bit difficult issue nowadays. According to forbes.com the number of new positions in cyber security field in the world will increase 18 percent in the following 5-year period. However, there will not be enough educated people in that period. When the demand is increasing the salary will surely increase, so it will not make sense for MSSPs to increase the number of employees in parallel to the number of customers. It makes sense to give higher priority to advance security issues like investigation of IPS signatures, malware analysis or DDOS threshold analysis to make a difference and increase the security level of the customers. To be able to give higher priority to these topics, the operational activities need to be reduced and policy change is one of the biggest operational activity. The operational activities also lead to higher turn over rates, so to make it low MSSP must give superior importance to new and advanced security issues. Managed Security Service Providers (MSSPs) are increasingly turning to firewall automation solutions to revolutionize their cybersecurity offerings. With the ever-evolving threat landscape, the demand for robust and efficient security services is at an all-time high. Firewall automation provides MSSPs with the tools they need to effectively manage and secure their clients’ networks. By leveraging firewall automation solutions, MSSPs can streamline their operations, enhance response times, and reduce the risk of human errors that can lead to security vulnerabilities. These solutions enable automated rule configuration, updates, and threat response, allowing MSSP teams to focus on higher-value tasks such as threat analysis and strategic planning. Moreover, firewall automation ensures consistency in security policy enforcement across multiple client environments, which is crucial for maintaining compliance standards. This not only elevates the level of security provided but also reinforces client trust in the MSSP’s capabilities. In a landscape where every second counts, firewall automation empowers MSSPs to proactively safeguard their clients’ networks from emerging threats. It’s a synergy of human expertise and cutting-edge technology that paves the way for stronger cybersecurity and more agile MSSP services. In conclusion, for MSSPs to make a more profitable business, to make a difference, to be able to give advance security services and not increasing the number of employee need as the number of costomers increase they need to make this security policy management and policy change activity is an automated activity.
Why Do Many Firewall Policy Automation Projects Fail?

With the development of new digital technologies and digital transformation the number of new policies be requested on firewalls has increased a lot. When there are high number of requests to be handled, this task becomes an operational activity. It makes sense to automate any operational activity like firewall policy changes and there is a tendency of making this activity an automation activity nowadays. Apart from that, although there are lots of projects going on the success rate of these policy automation projects is not so high. In this post we will be trying to focus on what may be the reasons of that. Why Do You Need Policy Automation People opt for firewall policy automation primarily to enhance cybersecurity efficiency and effectiveness. Automating firewall policies simplifies rule management, reduces human errors, and ensures consistent policy enforcement across complex networks. It also enables rapid responses to emerging threats, minimizing potential damage. Furthermore, automation allows security teams to allocate their time and expertise to more strategic tasks, like threat analysis and risk mitigation, rather than mundane administrative work. Ultimately, firewall policy automation is driven by the need to strengthen network security, streamline operations, and keep pace with the evolving threat landscape, enabling organizations to better protect their digital assets. There are several reasons that may cause these automation projects to be failed. One of the main reasons is the complexity of the customer environment. The other reason is lack of knowledge on the people running these projects. And finally the last reason is customer prioritites or lack of confidence to the vendor coupled with. To begin with in a traditional network there are L2 and L3 devices like routers, switches and firewalls responsible from routing. In a small-sized network creating a topology map and so finding any path to any destination may be easy. However, in corporate environments the situation is somehow different. There are private and public cloud infrastructures nearly in all the enterprises; Vmware NSX, Cisco ACI, Amazon, Azure infrastructures are so widespread and just collecting routing data from L3 devices is not enough anymore. Apart from that, there may exist L2 firewalls in the network and the solution must understand and discover these L2 firewall devices to create policies on them. Policy-based routing and static routes applied on the servers are also nightmare for the consultants of such projects since the path analysis requires source IP address information also. Since there are lots of non-standard configurations or applications on today’s network topologies the complexity is high and this is one of the reasons why many firewall automation projects fail. As to knowledge on the people running project. Firewall Automation projects may necessitate customer technical people involvement since the complexity of the topologies is high. However, most of the time senior people may not attend these sessions and there may be no written materials to follow to discover the network topology. Since there are lots of vendors for firewalls and other L3 devices this lack of knowledge indeed is inevitable. The consultant may know Fortinet, Palo Alto firewalls and Cisco switches well and the customer may have Checkpoint firewalls and HP switches in place and in that case the consultant will need to find information on the internet or from the people inside. This lack of necessary knowledge causes the projects to last long time and some may fail also. Finally, customer priorities, lack of confidence to the vendor coupled with are also the reasons. Customers may prioritize the analyzer part of the solution and start using it for general analysis of the firewalls. Getting the topology drawn by the system or getting unused rules data to investigate it further. Apart from that there may be lots of projects going on in parallel and the implementation of the automation part of the system may fall behind. The lack of confidence to the vendor relates to making the solution responsible for production activity and probability of downtime due to the solution. However, that’s why automation comes to play and reducing downtime due to human error. A dilemma case. In some cases resistance to make things to automate and to keep what they are doing as it is may also be a reason, but this situation be changed surely. Making policy changes to be done automatically is a need in today’s complex network topologies. There are several policy automation projects going on and as it it is mentioned in this post there may be several reasons behind that. Making policy change automation starts with choosing a solution that is robust, stable and scalable and easy to integrate in all kind of environments.