RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

ICT services

Your clients are obliged entities, so their obligations reach you through contracts. Whoever sorts this out first wins the work.

What the Act requires of this sector

Management of information and communication technology services between businesses is a separate Annex I sector. The competent authority is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA), and the competent CSIRT is the national cyber security centre (NCSC-HR).

This sector has a dual role. You are a covered entity under the Act, and at the same time a supplier to clients who are covered themselves. Their measure 8, supply chain security, translates into requirements towards you: security clauses in the contract, a right to audit, an obligation to report incidents, and evidence of vulnerability management.

In practice that means showing the same evidence twice, once to your own auditor and once to clients who ask for it in questionnaires. It is therefore worth arranging it so that it serves both.

Where this sector usually gets stuck

Remote access to clientsThe biggest risk and the most common finding in a client audit.
Contracts without security clausesThe client must have them, so they will ask you for them.
No records of your own measuresWithout evidence it is hard to answer a client questionnaire.

What we do for you

01Your own compliance with the law02Rules and records for remote access to clients03A template of security clauses for contracts04An evidence file for answering questionnaires05Training the team for work at obliged entities

Who from the sector falls in scope

WHOCATEGORYNOTE
Managed service providersEssential or importantBy size
Managed security service providersEssential or importantBy size; the audit certificate is a separate procedure before the Information Systems Security Bureau
Digital service providers from Annex IIImportantOnline marketplaces, online search engines and social networking services platforms

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · UNITED STATES AND SWEDEN, JULY 2021

Kaseya: one remote management tool, about 1,500 companies hit

Attackers exploited a vulnerability in the tool ICT providers use to manage client machines remotely and pushed ransomware to every client at once. Around fifty providers and some fifteen hundred of their customers were affected. Swedish retailer Coop closed about 800 stores because the tills would not work. When you sit inside somebody else’s network, your vulnerability becomes their outage, and sooner or later that ends up in the contract.

SOURCE: CISA and FBI joint advisory on the exploitation of Kaseya VSA, July 2021.

Frequently asked questions

The questions ICT service providers ask first, mostly about client contracts and remote access.

Are we in scope, or only our clients?

Managed service providers and managed security service providers are themselves within the scope of the law. On top of your own obligations you inherit those that pass to you through client contracts.

What do clients ask for in contracts?

Security clauses, an obligation to report incidents within their deadlines, a right of inspection, a list of subcontractors and rules for remote access.

How should remote access to clients be arranged?

Named accounts, multi factor authentication, access on request and a record of every session. It is the most common finding in a client audit, and the accountability is yours.

Do we need our own evidence file?

You do. Without records of your own measures you answer every client questionnaire from scratch, and differently each time.

Are we an essential or an important entity?

It depends on the service and the size. Managed service providers and managed security service providers sit in the same Annex I sector and are categorised by the same test: large entities are essential, medium-sized ones important.

What may clients require of us under the supply chain measure?

Security clauses in the contract, a right to audit, evidence of vulnerability management and an obligation to report incidents. Sub-measure 8.3 requires that, and the client is obliged to check how you meet those clauses, under sub-measure 8.4.

Do we have to keep a supplier register of our own?

You do, because you are a covered entity yourself. Sub-measure 8.2 requires the identification of all direct suppliers and service providers, so the chain runs on to your own subcontractors.

Does a certificate help with client questionnaires?

It helps considerably, because the statement of applicability covers much of what is asked. But a certificate does not replace answers on incident reporting deadlines and contract clauses, which the Regulation requires and the standard does not.

Related pages

The pages that set out what the Act and client contracts require of ICT service providers.

Let us look at the last questionnaire you received.

Half an hour, no obligation. We look at what your clients require by contract and how much of it you already have.

Book a callINFO@RISKORIA.EU · +385 97 737 1345