a padlock

Updated: IT security survey opens Infosec

Firms could do more to improve security, according to survey on IT breaches

Written by Phil Muncaster at Infosec

Organisations' approach to information security has matured dramatically over the last two years, but fundamental contradictions in security management still exist which are undermining their efforts at data protection, according to the latest Information Security Breaches Survey.

Launched at the annual Infosecurity Europe trade show in London today, the biennial report, carried out on behalf of the department for business enterprise and regulatory reform (Berr) found widespread boardroom recognition of information security, leading to an increase in spending from two per cent of total IT budget in 2002, to seven per cent today.

However, despite firms now investing in technologies like software scanning (98 per cent), wireless network encryption (94 per cent) and back-ups (99 per cent), over three-quarters are still unaware of the best practice international ISO 2700 security standard.

"There are gaps between the aspirations of firms and what they are actually putting into practice," said PWC partner Chris Potter. "Eighty one per cent said they believe security is a high priority but only 55 per cent actually have a documented security policy."

Data breaches were identified as the biggest challenge facing firms today, but although 77 per cent said protecting customer information is a priority, only eight per cent encrypt data stored on laptops, the survey found.

A lack of dedicated IT security professionals and the ever-evolving nature of threats are major factors adding to the risks facing firms today, argued Potter.

He recommended firms first seek to understand the threats facing them by access the right knowledge sources, and then carry out risk assessments and implement integrated security controls.

Security awareness was highlighted as a major element of effective security risk management strategies. Although firms are trusting their staff more by reducing blocks on instant messaging and opening up internet access, training policies still lack vigour, the report found.

"What we find is that we may have got the technical problems solved but we need to raise the human element," said Martin Smith of The Security Company, which was also involved in producing the survey. "I wonder how much of firms' [awareness raising] is … just ticks in boxes – we need to move from raising awareness to changing behaviour."

However Mike Smart of security vendor Secure Computing argued that technology controls are an important part of an effective security risk management program.

"Policy-based actions like encrypting content become very important, and technology can help to stop users clicking on a certain link, to [mitigate the risk] from social engineering attacks" he explained.

Also at the event, newly created organisation the Information Security Awarenes Forum launched a new information sharing portal to allow experts to share views and knowledge and to help in promoting awareness.

Infosecurityadviser.com includes product news and reviews, expert blogs, and an "ask the experts" feature.

Mike Maddison, UK head of security and privacy services at consultancy Deloitte, said that organisations need to coordinate their response to security issues across multiple departments, which can be challenging.

"As there is no software patch for people it is clear that the solution to managing such a risk requires flexibility and is as much about people and culture as process and technology," he added. "Consumer concerns and media attention will continue to make this a high profile issue and could result in increasing legislation."

In related news the growing risk to firms of unchecked internet use at work was highlighted today by new research from security vendor Sophos. Its latest Security Threat report found that in the first three months of this year the vendor blocked the equivalent of a new infected web page every five seconds, compared with one every 14 seconds last year.

Tags:

Further reading

Infosecurity Europe show to focus on data breaches

Annual trade show will see the launch of the annual Information Security Breaches Survey   More...

Firms' disaster recovery plans are disasterous

Survey carried out on behalf of Infosec show finds a dismal disaster recovery landscape   More...

IT leaders ignorant of WEEE

Nearly three quarters of IT professionals are unaware of the directive, according to new research   More...

Security awareness-raising forum is launched

New organisation aims to reduce human failings and improve organisations' security   More...

Related articles

UK firms at risk from the 'enemy within'

Staff still the weakest link in the IT security chain   More...

Infosec: UK firms winning security battle

New survey shows incidence and costs of attacks falling   More...

Intel outlines ESP project

Everyday Sensing and Perception initiative aims to make computers more 'aware'   More...

Infosec: Reputation driving information security

Security is now everyone's problem   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement