Is it worth the paper it is written on?
Another thing I saw at RSA was some vendors offering guarantees with their products. One IPS vendor is offering a 60 day guarantee if you buy their product and are not protected against an attack. Another patch vendor in conjunction with a major insurance carrier is offering up to a million dollars of coverage or up to what you paid for the product (whichever is less, I believe), if they don't deliver a patch within a guaranteed period of time. From my days in the hosting and managed services business, I am a big believer in SLA's that a customer can count on. However, when you look at these types of guarantees, I am afraid they are long on the marketing and short on the protection. A major security breach is going to cause a lot more damage than just the purchase price of the product. Additionally, some of them have so much hair attached that it would be a very cold day you know where before you can collect on them. I guess the market will determine whether these are the beginning of a new era of SLA's in security or just a cheap marketing trip.






Comments