
When cybersecurity is discussed in Norwegian businesses, the conversation often quickly turns to technology. Surveillance. Systems. Tools.
In practice, however, the security level is often decided earlier and in a completely different place:
in agreements.
Most businesses has a security provider. The contract is signed, the service is operational, reports are delivered. Nevertheless, many lack clear answers when the most basic questions are asked:
These are questions many people feel they have, but few have entirely clear answers to. And precisely because of this, they are often postponed. Not because they are complicated, but because they require clarity in roles, responsibilities, and expectations.
The central question of control is simple, but often uncomfortable: Is the business actually getting what it's paying for?
Many cybersecurity agreements were entered into at a different stage of the company's development than today.
Over time, needs evolve, the threat landscape becomes more complex, and expectations for interaction between IT, management, and suppliers increase.
However, the agreement often remains unchanged.
This became clear during the work with BlueNord. Security services were in place, but there was a need for greater clarity around responsibility, interaction, and content – particularly at the interface between operational activities and advisory services.
When security is reduced to a service that «just works», it becomes difficult to make demands – and even harder to make the right ones.
Security deliveries are increasingly about more than operational activities. Businesses are not only requesting monitoring and incident management, but also ongoing assessments, prioritisation, and advice relevant to their own business.
This includes, among other things:
For BlueNord, it was crucial to have precisely this clarified in the agreement: a formal SOC delivery, combined with real advice and proactive collaboration – also directed at the company's management.
For us, this is about more than just increased security in a technical sense. The updated agreement provides us with better protection, greater robustness – and not least, security efforts that are more closely aligned with the organisation's actual goals and priorities.
IT Manager BlueNord, Helge Zahl
This presumes agreements that clearly distinguish between operational delivery and advice, and which describe how these functions will complement each other over time.
When existing agreements no longer meet requirements, broad competition is often seen as the only solution. This is not always correct. In many cases, targeted negotiation can yield the greatest effect – assuming that functional areas, responsibilities, and finances are viewed in context.

In working with BlueNord, emphasis was therefore placed on a targeted negotiation process, with a clear focus on content rather than volume. The questions asked were fundamental, yet crucial:
The result was not greater certainty “on paper”, but an agreement that to a greater extent reflects the company's actual current needs – and provides better conditions for management, collaboration, and further development. After this work, it makes sense to consider the way forward. Only then will one know what which may potentially be compared.
The value often lies in concretising what the delivery should actually include, how the collaboration will work in practice – and ensuring that the finances are commensurate with the responsibility. Only then can one be sure that one is getting what one is paying for.
Knut Riiber, Senior Advisor Adite
It is not always obvious when a security arrangement should be reviewed. Often, the solutions work fine in everyday life until they don't.
A useful exercise could therefore be to ask yourself a few simple questions:
If you have to pause to think, hesitate with your answers, or get conflicting internal responses, it's often a sign that the deal warrants closer scrutiny.
This is demanding work that takes time and capacity in an already busy everyday life. At the same time, it is precisely here that the foundation is laid for management, predictability, and real control over risk. Addressing agreements is rarely the most urgent task at hand – but it is often what matters most over time.