escrow presentation
TRANSCRIPT
Escrow SolutionsEscrow Solutions
NCC Group PlcManchester Technology Centre Oxford RoadManchesterM1 7EFwww.nccgroup.comwww.nccgroup.com
Lucy Davidson Lucy Davidson
Key Account ManagerTel: +44 (0) 161 209 5256Mobile: 07807066642e-mail: [email protected]
2Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Agenda
About NCC Group
The need for software escrow
What is software escrow?
Benefits
NCC Group Escrow Solutions
Primary Components Of Escrow Agreement
What Can You Do if a release event is triggered
Why is testing important?
NCC Group Verification Services
Effect Of Current Economic Climate
Risk assessment / escrow policy
Current Agreements
3Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
About NCC Group
What we do: independent IT assurance, security and consultancy services - over 15,000 clients worldwide including 94 of the FTSE 100
USP: no ties or relationships to hardware or software suppliers - focus on developing intelligent solutions & building lasting partnerships with clients
Size: based in Manchester with offices throughout the UK, Europe & California, currently employ 350 + staff worldwide
History: formed in 1999, listed on London Stock Exchange since July 2004, consistent track record of solid growth. July 2007 full listing
Our business: three complementary divisions: Escrow Solutions, Assurance Testing and Consultancy NCC Group is the world’s largest Software escrow
provider
4Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Our services
Escrow SolutionsEnsure business-critical material or source code is protected and
accessible should a key supplier failConfirms material held is properly protected - verify it can be
rebuilt from components
Assurance TestingTest & monitor system, network & web site performance to ensure
effective, robust and delivering optimum performanceEthical security testing of networks and applications and security
policies in practice to ensure organisations safe from threat of unauthorised access
ConsultancyProvide advice at all levels to help organisations improve
performance through effective use of IT & business processesProtect organisations against a variety of risks through
development & implementation of effective plans and compliance with relevant standards
5Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
The need for software escrow
The failure of any these applications would result in financial or operational loss
Therefore organisations are reliant on the owner / supplier to provide support and maintenance
BUT they will only supply the ‘object code’ - the ‘source code’ is required to support and maintain
However if the owner is no longer willing / able to provide support in the event of failure…..
And there is increasing scrutiny on corporate governance and risk management – Sarbanes Oxley, Basel II, FSA Rules and Regulations
Source: Vision One Research 2007
6Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
What is software escrow?
Legal agreement between supplier, licensee & escrow provider (distributor if applicable)
Supplier obligated to deposit source code in escrow and to keep updated
‘Trigger Events’ defined in the agreement where source code released to licensee such as: Liquidation Ceasing to tradeFailure to meet maintenance obligations IPR assignment (if new owner provides
no escrow protection)
7Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Benefits for the licensee
‘Insurance policy’ against the unpredictable IT market
Allows continuing maintenance of critical applications in event of release of code
Provides protection during investment in IT development
Essential part of business continuity and disaster recovery planning
Provides leverage against supplier who defaults on contractual obligations / IPR’s assigned to a new supplier
8Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
NCC Group Escrow Solutions
Software EscrowSingle and multi licensee agreementsHolding AgreementsDevelopment agreementsSpecialised outsourcer and distributor agreementsStaggered release agreements to protect distributors and end-usersWeb sites and web applications covered
Information EscrowProduct designsManufacturing processesMarketing information
Copyright Protection Agreement
NCC Group Escrow Solutions are flexible and can cover all situations
9Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Primary Components of Escrow Agreement
Owners Duties and Warranties Initial deposit within 30 daysFrequency of future deposits (yearly / quarterly)Scope of material to be depositedWarranty of IPR ownership in the material
Licensee ResponsibilityNotify NCC Group if deposit update requiredConfidentiality undertaking in event of release
Release Events
Release Process Independent expert determination in the event of disputeTime bound process
10
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Primary Components of Escrow Agreement
Integrity Testing and Full Verification
NCC Group Liability / Indemnity
TerminationOwner cannot terminate without licensee consent
SchedulesPackage NameNCC Escrow Fees
• The proportion of fees paid by each party
11
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
What can YOU do if a release is triggered?
Get a release of the source code deposit:Appoint another software supplier to take over maintenance ORTake over support and maintenance in-house i.e. be prepared in the case that the application subsequently fails or
needs maintenance
Use the potential option of release to negotiate a good deal with the new Owner of the IPR, introduced through NCC Group
Remember that Escrow is a leverage tool in cases of: Issues with support and maintenanceChange of IPR ownership, negotiate good terms with new supplierSoftware Owner liquidation – leading to change of IPR Ownership
12
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Why is testing important?
Only the depositor knows what’s stored on the deposited media
Mistakes are often made when preparing the deposit
Vital information such as build scripts can be left out
The scope of the material to be deposited can be misunderstood
It’s too late to ask questions if the supplier has gone out of business…
13
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
NCC Group Verification Services
Full Verification: We observe complete build of application at supplier's site Every detail of environment & build process detailed in a comprehensive report,
describing every step involved in building the source code into the working application
Escrow Now: Recommended where source code maintenance would be undertaken by a third party Full Verification with additional assurance of build in independent secure location - our
secure test laboratory Report also provides information on timescales, technical skills & costs of rebuild to assist
with selection of suitable third party
Escrow Complete: Recommended where source code maintenance would be undertaken by the licensee Full Verification with additional assurance of build repeated in licensee's environment Source code collected & built at supplier's site and then built & installed at user's site
Integrity Plus: Recommended for other material which cannot be checked through build process / during
software development Intelligent collection & audit of material at supplier’s site
All escrow deposits are integrity tested as standard to ensure accessible and virus free
14
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Effect Of Current Economic Climate
Software companies need cash to develop new applications to survive
Access to credit is the lowest it’s ever been
Small and mid size companies are under real threat of closure due to falling profits and not being able to finance debt
Your company is reliant on those software owners
If your supplier fails the effect on your business could be catastrophic... e.g. Zavvi uses EUK (Woolworths) EUK stops supplying Zavvi has to close online sales as they have no stock and are now being run by
administrators with 22 stores already closed
200% increase in release events in last ¼ of 2008
15
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Act on Escrow NOW
Nortel has gone into Chapter 11:
Nortel is the first major vendor in the ICT industry to have gone into administration as a direct result of the credit crunch.
http://www.electronicsweekly.com/Articles/2009/01/14/45269/nortel-goes-into-administration.htm
1 in 5 software companies could go out of business according to a recent survey by Plimsoll
http://www.computerweekly.com/Articles/2008/04/24/230427/recession-could-force-uk-software-firms-out-of-business.htm
Autodesk has joined the growing number of technology companies to cut staff, announcing today that it will reduce its workforce by 750
http://www.vnunet.com/vnunet/news/2234114/autodesk-cuts-750-jobs
16
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Risk assessment & escrow policy
Assess business criticality of application (guidance sheet provided):Initial procurementMajor upgradeEvery 12 months
Educate and involve business users in evaluating need for escrow & managing protection once in place
Educate and involve sales staff in evaluating need for escrow protection to assist sales and protect distributor arrangements
Check required protection is in place through regular risk management and business continuity audits
17
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Escrow Clause
The [owner] shall lodge the source code (documents, materials and any other relevant information) of the [software package as defined within the software contract] with NCC Escrow International Limited upon the attached terms and conditions. The escrow agreement shall be completed as soon as practicable and in any event within [30 days] from the date of this agreement. In addition, should the [licensee] require it, the [owner] hereby agrees to cooperate in carrying out full verification testing as defined in and in accordance with the terms of the escrow agreement.
18
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Questions & AnswersQuestions & Answers
www.nccgroup.comwww.nccgroup.com
19
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
20
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
21
Commercial in Confidence - © Copyright 2009 NCC Group Plc - all rights reserved
Your Account Manager
Lucy Davidson
NCC Group plc
Manchester Technology Centre, Oxford Road,
Manchester M1 7EF
UK
+44 161 209 5256
www.nccgroup.com