I have worked with many Consulting Firms.
Here is the problems I see:
1. Consluting firms have no idea what their doing usually.
2. Consulting firms have no idea what a "real" Information Security program is.
3. If they do know what a real information security program is they dont want to implement it for their clients due to the fact that it will reduce the need for said consultants. Unless of course Said consulting firms have management contracts with their clients, meaning the clients can not manage their own systems by contract. Then the firms will lock down the systems tighter than a drum to avoid needless maintainence due to user error or otherwise.
4. Consluting Firms Prey on users ignorance, and usually like to see users "mucking" with their systems to promote more business. i.e. users hosing their systems. see line 3
5. Consluting firms are in it for the money, not the ethics or client relations.
6. When was the last time you seen a consulting firm hand control of managed systems With "PROPER" documentation to their clients?
nuff said
I have worked with many Consulting Firms. Here is the problems I see: 1. Consluting firms have no idea what their doing usually. 2. Consulting firms have no idea what a "real" Information Security program is. 3. If they do know what a real information security program is they dont want to implement it for their clients due to the fact that it will reduce the need for said consultants. Unless of course Said consulting firms have management contracts with their clients, meaning the clients can not manage their own systems by contract. Then the firms will lock down the systems tighter than a drum to avoid needless maintainence due to user error or otherwise. 4. Consluting Firms Prey on users ignorance, and usually like to see users "mucking" with their systems to promote more business. i.e. users hosing their systems. see line 3 5. Consluting firms are in it for the money, not the ethics or client relations. 6. When was the last time you seen a consulting firm hand control of managed systems With "PROPER" documentation to their clients? nuff said