Research - CIOInsight
Home arrow Research arrow Page 2 - Security Relaxes as IT Threats Increase
RECENT NEWS



CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

  Research


Security Relaxes as IT Threats Increase



By Allan Alter


  Table of Contents:
  1. Security Relaxes as IT Threats Increase
  2. ' Increasing Awareness is not '

Companies are facing IT threats at startling rates and IT's efforts to protect data continues to lag, according to a recent survey.

Rate This Article:
Add This Article To:

Security Relaxes as IT Threats Increase - ' Increasing Awareness is not '


( Page 2 of 2 )

Enough">

Says Paller of the SANS Institute: "Awareness education doesn't work. The current security awareness programs are not effective at keeping people from making the mistakes that cause their computers to become zombies.

"Managers are right to resist security awareness training that's ineffective. Why should I send a person to training if they won't do anything differently?"

Alarming Results:

Finding 1
Four years after Sept. 11, not all IT executives remain on their guard.

Finding 2
Negligence is the biggest security worry for IT executives

Finding 3
Companies are failing to take steps to improve security awareness.

Finding 4
Security isn't truly strategic until it's integrated with risk management.

Finding 5
Companies still aren't going the extra mile to keep customer and employee data private.

Finding 6
Technologies that prevent identity theft lag behind other security technologies.

DeZabala notes that it is easier to justify spending on technology than on training.

"If you are skeptical about these programs, will you be criticized if a security event occurs, and you've spent your money on training and awareness rather than on something that's technological or operational in nature?" he said.

Our survey suggests that if companies want to lower the risk of negligence, carelessness and management resistance, they need to put security into a broader, more strategic perspective, rather than just take a defensive posture.

Companies with a real security strategy—especially one that's grounded in corporate risk management—typically take more steps to protect themselves from employee carelessness and ignorance.

Does cyberterror matter to counterterrorists? Click here to read more.

Such companies are much more likely to provide training and security updates, and to develop policies regarding e-mail attachments and network access.

Harte-Hanks, for example, has taken many steps to raise employee awareness, from alerting employees about new threats, to brown-bag luncheons and asking employees to sign documents attesting to their security and confidentiality standards.

According to Siesel, the key is to show employees the direct impact a security lapse could have on them and their company.

"When people understand how their behavior can affect their customers, their company or themselves, they are more likely to take steps to protect them. They could lose stock value. The company could be shut down. We could lose important customers."

Companies that develop an integrated IT-risk management strategy are also more likely to establish responsibility for managing IT risk between IT and business managers, which helps to make sure that management will stand behind the company's IT security policies.

If, as Schneier says, companies need to create "a culture of security" from the top down, putting in the time and effort to work with executives to develop a real, workable security strategy appears a necessary step.

More Alarming Results:

  • 5.9 percent of the average IT budget is dedicated to security.
  • 64 percent have strengthened security in the wake of recent news reports on identity theft.
  • 37 percent of companies have been penetrated by spyware.
  • 72 percent rank careless or risky employee behavior as one of their top three security concerns.
  • 48 percent provide special training to employees who handle customer data.

    To download the survey results, click here.



     
     
    >>> More Research Articles          >>> More By Allan Alter
     


  • FEATURED SPONSORED VIDEOS

    FEATURED SPONSORED ARTICLES

    Erasable E-Paper Saves Trees, Cuts Costs

    Why Smart Companies Should Adopt the Lessons of Gaming

    Interest in Mobile WiFi Hotspots Fuels New Solutions

    A Closer Look at Public Cloud Security

    View More Articles

      Brought to You By
    Click Here




    EDITORS' PICKS

    LATEST STORIES


    Advertisement
    FEEDBACK
    Ziff Davis Enterprise RSS Feeds

    Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks