At this point, risks have been identified and prioritized, and response methods and cybersecurity controls have been selected to address them. The organization must now decide how it will procure those controls.
One of the biggest factors preventing organizations from improving their cybersecurity posture is cost. Therefore, organizations need to carefully examine their cybersecurity budget and ensure that the costs associated with selected controls are reasonable. To stay within budget, the organization must decide whether it is best to build, buy, or partner when acquiring the technology behind each control. The Build-Buy-Partner Framework is a standard strategic evaluation model used to determine how an organization should acquire new technology.
These decisions must be made by the appropriate authorities within the organization. In most cases, this responsibility falls to the Board of Directors or an equivalent group of senior managers and key stakeholders. However, while the ultimate decision regarding control procurement rests with executive leadership, subject matter experts (SMEs), including IT staff and external contractors, must also be involved to ensure the organization makes informed decisions.
As part of this framework, the IT and cybersecurity departments are kept informed by the designated Budget Authority. The Budget Authority should also use its communication channels to integrate SME opinions into the procurement process.
Depending on the size of the organization and the degree to which decision-making is centralized or decentralized, executive stakeholders may delegate some procurement authority to IT departments. For example, executive stakeholders may allocate funds directly from the cybersecurity budget to information security leadership and permit them to make purchases independently, provided that a reasonable return on investment can be demonstrated. Ultimately, it is up to the organization's leadership and key stakeholders to determine the specifics of the procurement process.
Build
There are many opportunities for organizations to build network and cybersecurity infrastructure in-house. The proliferation of open-source software has made this increasingly feasible, and many open-source cybersecurity platforms possess reputations that are as strong as, or even stronger than, proprietary alternatives.
For example:
- Routers can be built using pfSense or OPNsense.
- SIEM systems can be implemented using Wazuh or the Elastic Stack (ELK Stack).
- DNS filtering can be provided through Pi-hole.
- Intrusion detection can be performed using Snort.
- File integrity monitoring and host intrusion detection can be accomplished using OSSEC.
These are only a few examples of popular open-source security tools that form the backbone of many enterprise environments. Platforms such as Security Onion combine multiple security tools and capabilities into a unified platform, further simplifying security infrastructure management.
Organizations should take advantage of opportunities to build and configure as much of their infrastructure as practical. Doing so places greater control directly in the hands of the organization, providing increased visibility into infrastructure operations and stronger protection of privacy.
However, there are also disadvantages to the build approach. Appropriate personnel with the necessary skills must be available to install, configure, and maintain the security infrastructure. If in-house IT or cybersecurity personnel are unavailable, implementation will need to be outsourced to a third party, such as an IT contractor. Under no circumstances should inexperienced personnel attempt to configure an organization's entire cybersecurity infrastructure. Doing so may lead to significant misconfigurations and create more vulnerabilities than existed originally.
Additionally, some level of purchasing is almost always required, even when using a build strategy. Many network administrators, particularly within smaller environments, make excellent use of recycled hardware by repurposing quality desktop computers as servers. Nevertheless, organizations will often need to purchase new devices or additional hardware components. As a result, while building infrastructure can significantly reduce cybersecurity costs, it rarely eliminates them entirely.
Buy
Many organizations, both large and small, choose to purchase security platforms and infrastructure rather than build them. The primary justification for doing so is often the desire to save time on configuration, reduce operational complexity, or gain access to advanced features identified as valuable by stakeholders.
A wide range of proprietary cybersecurity technologies support modern organizations. Splunk remains one of the most well-known SIEM solutions in the commercial sector. Cloud security platforms such as Microsoft Purview and Microsoft Sentinel provide highly granular security capabilities for enterprise cloud environments. Organizations that cannot support on-premises infrastructure frequently purchase virtual machines hosted on highly available cloud platforms such as Microsoft Azure Virtual Machines or Amazon EC2.
Network infrastructure can be particularly complex to configure in environments that lack dedicated network engineers. As a result, many smaller organizations choose to purchase routers, firewalls, and switches that provide secure functionality with minimal configuration effort.
Although proprietary technologies can represent a substantial investment, they often reduce costs over the long term by decreasing the need for on-premises infrastructure and reducing staffing requirements associated with maintenance and uptime management.
Every organization's digital environment is unique. Therefore, executive leadership, senior management, and IT subject matter experts must work together to determine whether building or buying is most appropriate. Factors such as network capacity, regulatory requirements, staffing availability, technical expertise, and physical infrastructure constraints all influence this decision.
Partner
The final option is often the most expensive but also places the greatest burden on external providers rather than the organization itself.
Outsourcing IT and cybersecurity functions to third parties is a popular solution, although it introduces its own set of risks. There are several levels of outsourcing information security capabilities. Some organizations may hire contractors to establish their infrastructure while retaining responsibility for ongoing monitoring and maintenance. Other organizations, particularly smaller ones, choose to fully outsource information security management to Managed Security Service Providers (MSSPs).
MSSPs can not only deploy the initial infrastructure but also provide ongoing monitoring and support, often on a 24/7 basis. These organizations typically employ teams that operate from Network Operations Centers (NOCs) or Security Operations Centers (SOCs). Such teams monitor client environments and provide services including incident response, triage, troubleshooting, proactive monitoring, threat hunting, and day-to-day security operations management.
Depending on the service agreement, organizations may also delegate infrastructure hosting and disaster recovery responsibilities to the provider. Outsourcing disaster recovery capabilities in this manner is commonly referred to as Disaster Recovery as a Service (DRaaS) and can significantly reduce operational burdens.
However, this option also presents risks. Some organizations have encountered difficulties with MSSPs due to misaligned expectations, communication challenges, or insufficient understanding of industry-specific business requirements.
Because MSSPs operate as commercial businesses, they must balance service quality with profitability. In some cases, providers may allocate minimal resources to client environments, resulting in a level of service that fails to meet expectations. Furthermore, while organizations may benefit from access to experienced cybersecurity professionals, there is no guarantee that every MSSP employs personnel with the same level of expertise. Organizations also have limited visibility into the provider's internal procedures and staffing practices.
Despite these concerns, many organizations conclude that the benefits outweigh the drawbacks and determine that partnering with an MSSP is the most cost-effective solution available.
If an organization chooses to engage any third party for cybersecurity services, it must ensure that the agreement clearly defines the responsibilities and expectations of both parties. As with any third-party IT relationship, organizations should establish a shared responsibility model that specifies ownership of security duties and includes contractual provisions such as the right to audit or right to verify. Organizations should thoroughly vet any third party before entrusting them with responsibility for IT or cybersecurity operations.
