Purchasing and consultancy

IT agreement for business: What is required for good cybersecurity?

Procurement and consulting are about making the right choices when decisions are complex – particularly in IT and telecoms.

When cybersecurity is discussed in Norwegian businesses, the conversation often quickly turns to technology. Surveillance. Systems. Tools.

In practice, however, the security level is often decided earlier and in a completely different place:
in agreements.

Most businesses has a security provider. The contract is signed, the service is operational, reports are delivered. Nevertheless, many lack clear answers when the most basic questions are asked:

  • Who is responsible when something happens?
  • What is actually delivered – and what is outside the scope of the agreement?
  • When is delivery operational – and when is it advisory?

These are questions many people feel they have, but few have entirely clear answers to. And precisely because of this, they are often postponed. Not because they are complicated, but because they require clarity in roles, responsibilities, and expectations.

The central question of control is simple, but often uncomfortable: Is the business actually getting what it's paying for?

Agreements that do not keep pace with reality

Many cybersecurity agreements were entered into at a different stage of the company's development than today.
Over time, needs evolve, the threat landscape becomes more complex, and expectations for interaction between IT, management, and suppliers increase.

However, the agreement often remains unchanged.

This became clear during the work with BlueNord. Security services were in place, but there was a need for greater clarity around responsibility, interaction, and content – particularly at the interface between operational activities and advisory services.

When security is reduced to a service that «just works», it becomes difficult to make demands – and even harder to make the right ones.

More than monitoring and response time

Security deliveries are increasingly about more than operational activities. Businesses are not only requesting monitoring and incident management, but also ongoing assessments, prioritisation, and advice relevant to their own business.

This includes, among other things:

  • Support for management in understanding risk
  • proactive input, not just post-event reports
  • clear frameworks for how collaboration will actually work in practice

For BlueNord, it was crucial to have precisely this clarified in the agreement: a formal SOC delivery, combined with real advice and proactive collaboration – also directed at the company's management.

For us, this is about more than just increased security in a technical sense. The updated agreement provides us with better protection, greater robustness – and not least, security efforts that are more closely aligned with the organisation's actual goals and priorities.

IT Manager BlueNord, Helge Zahl

This presumes agreements that clearly distinguish between operational delivery and advice, and which describe how these functions will complement each other over time.

When targeted negotiation delivers the most value

When existing agreements no longer meet requirements, broad competition is often seen as the only solution. This is not always correct. In many cases, targeted negotiation can yield the greatest effect – assuming that functional areas, responsibilities, and finances are viewed in context.

In working with BlueNord, emphasis was therefore placed on a targeted negotiation process, with a clear focus on content rather than volume. The questions asked were fundamental, yet crucial:

  • What will the delivery actually contain – operational and advisory?
  • How will the collaboration work in practice?
  • And what cost level is reasonable when viewed against responsibility and scope?

The result was not greater certainty “on paper”, but an agreement that to a greater extent reflects the company's actual current needs – and provides better conditions for management, collaboration, and further development. After this work, it makes sense to consider the way forward. Only then will one know what which may potentially be compared.

The value often lies in concretising what the delivery should actually include, how the collaboration will work in practice – and ensuring that the finances are commensurate with the responsibility. Only then can one be sure that one is getting what one is paying for.

Knut Riiber, Senior Advisor Adite

Security starts before technology is deployed

It is not always obvious when a security arrangement should be reviewed. Often, the solutions work fine in everyday life until they don't.

A useful exercise could therefore be to ask yourself a few simple questions:

  • Do you know specifically where the responsibility lies if something actually happens?
  • Is it clear what you are paying for – and what is excluded from the agreement?
  • Do you know when delivery is about operations and when you should actually expect advice and support?
  • Has the agreement evolved in step with the business, or has it effectively been left for several years?
  • Are you confident that the cost level is proportionate to the responsibility the supplier has?

If you have to pause to think, hesitate with your answers, or get conflicting internal responses, it's often a sign that the deal warrants closer scrutiny.

This is demanding work that takes time and capacity in an already busy everyday life. At the same time, it is precisely here that the foundation is laid for management, predictability, and real control over risk. Addressing agreements is rarely the most urgent task at hand – but it is often what matters most over time.

Contact us

    Contact Adite