Research - CIOInsight
Home arrow Research arrow Security Relaxes as IT Threats Increase
  Research


Security Relaxes as IT Threats Increase
By Allan Alter


  Table of Contents:
  1. Security Relaxes as IT Threats Increase
  2. ' Increasing Awareness is not '

Rate This Article:
Add This Article To:
Security Relaxes as IT Threats Increase
( Page 1 of 2 )

Companies are facing IT threats at startling rates and IT's efforts to protect data continues to lag, according to a recent survey.

The news on the IT security front is alarming. Recent months have seen one report after another of companies exposing, selling or simply losing customer data to criminals.

The reason: The security threat has changed, according to Bruce Schneier, CTO of Counterpane Internet Security Inc., of Mountain View, Calif.

In the past three years, he says, "criminals have taken over from hackers." The latest twist in cybercrime is online extortion.

The August 2 issue of "Newsweek International" reported that online gambling sites have been hit by extortionists who threaten to shut down their Web sites with denial-of-service attacks unless the gambling sites pay off the blackmailers.

Resource Library:
According to Alan Paller, director of research at the SANS Institute, an IT security educational organization located in Bethesda, Md., banks and online retailers have also quietly paid off online extortionists, whose demands have, to date, ranged as high as $1 million.

And in June, the U.K.'s National Infrastructure Security Co-Ordination Centre warned that Trojan horses (transmitted by e-mail or through Web sites) that appear to come from legitimate sources, and so can evade antivirus software and firewalls, were specifically targeting individuals who work with sensitive "commercially or economically valuable information."

Click here to read about how some customer data may be too risky to keep.

The latest update from IBM Corp.'s "Global Business Security Index" indicates that such targeted attacks are a fast-growing percentage of the 237 million infected e-mails and attacks perpetrated in the first half of 2005.

In light of these reports, our latest security survey of nearly 300 IT executives presents some pretty grim findings.

Three out of ten respondents admit that their company's attitude toward security has become more relaxed as the events of Sept. 11 fade into the past.

Two-thirds report some kind of security breach, from penetration by viruses or spyware, to lost data and inappropriate access.

And while security experts are encouraged to see that the sort of carelessness and negligence that lets hackers and thieves get past a company's defenses is now recognized as the top security issue problem.

"It's a good sign, a sign we're starting to see CIO awareness match actual risks," says Counterpane's Schneier.

Still, many companies aren't taking steps to improve awareness and education.

This last problem was also identified as a major concern in both Ernst & Young's 2004 "Global Information Security Survey" and in Deloitte's 2005 "Global Security Survey" of major financial services companies.

"What's disturbing is that while employee negligence is a big concern, training and awareness programs are not high on the radar screen," says Ted DeZabala, a principal in the security services group of Deloitte & Touche LLP, in New York City.

The IT executives and experts we spoke with agree that defending companies from attack and theft requires more than deploying security technology.

"It takes a combination of people, processes and technology, not one thing," says David Siesel, the CTO of the direct marketing group at Harte-Hanks Inc., a $1 billion media company based in San Antonio.

So why the reluctance to invest in security awareness and training?

Next Page: Increasing awareness is not enough.



 
 
>>> More Research Articles          >>> More By Allan Alter
 


 
 
FEATURED SPONSORED MESSAGE
 

    Microsoft Windows Server 2008 R2


    Building on the award-winning foundation of Windows Server 2008, R2 enables IT professionals to increase the reliability and flexibility of their server infrastructures.

    Access a trove of Microsoft resources, analyst white papers, and multimedia presentations on Windows Server 2008 R2.


FEATURED SPONSORED CONTENT

    Improve Communication and Collaboration

    Enable employees to more effectively collaborate and compete in a tough economy. Make communications and collaboration efficient, more secure, less expensive, and easier to manage.

    A Unified Communications deployment can help reign in the costs and the chaos by combining voice, data, fax, conferencing, and presence awareness into a single, versatile system.


BIZTECH 3.0
By Brian P. Watson
CIOs and the Consumerization of IT

New advice on how CIOs should bring consumer-focused technologies into the enterprise.
CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

Google CIO on IT's Role in Corporate Culture

RECENT NEWS

KNOW IT ALL
By Tony Kontzer
Internet Addiction: A Mental Illness?

A leading psychiatric group doesn't think so. But maybe it should. 


EDITORS' PICKS
 
 
LATEST STORIES

FEEDBACK


Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • Servers that cut energy costs by 95%? Cool.
  • Save time & money with Microsoft's cloud services.
  • Come see the Benefits of Desktop Virtualization on 3/18/10.
  • Simplicity is Power. Start simplifying with Citrix.
  • Register for WES 2010 by March 26 and save $200.
  • One number. One voicemail. Sprint Mobile Integration.
  • CDW Healthcare offers the IT solutions you need.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • eWEEK Quick LInks