As organisations move increasingly to cloud-based collaboration platforms, different kinds of security risks present themselves and require active management. Responsible SaaS vendors take the trust placed in them very seriously as one of their greatest assets - but on the client side there is still much which can be done to minimise exposure to breaches and hacks.
[caption id="attachment_23055" align="alignright" width="200"]
Gerald Beuchelt[/caption]
We caught up with Gerald Beuchelt, Chief Information Security Officer at LogMeIn, to discuss the issues that clients should be aware of - and he stressed the fact that responsibility for information security can never be fully outsourced to any tool:
“With the SaaS model, there’s no need for manual updates, the vendor is responsible and accountable for maintaining the overall quality and security of the platform. So that’s something that really makes it much more accessible and easier for smaller companies, a lot less resource intensive, [compared to choosing] an on-prem platform where you are responsible for maintaining the software and keeping it up to date.
“But SaaS doesn’t absolve the customer of the responsibility to do things right, with the software they subscribe to.”
Shared Responsibility, Shared Awareness
Deploying a communications platform like LogMeIn on a subscription basis manifestly makes things easier for the client, who can take advantage of the vendor’s ongoing work to secure the platform, and proactive engagement with security issues - such as their 18 month preparation plan for GDPR compliance, and provision of a Trust Centre to facilitate user due diligence, for example.
But clients still need to perform that due diligence for themselves, and indeed, Beuchelt stresses that technology is just one layer in the stack of defences against security breaches, accidental or otherwise. It’s more about the people and what they actually do with the tools they use, than the tools themselves:




