April 21, 2008 9:01 PM PDT

The new byword in infosecurity: Don't embarrass the boss

by Charles Cooper
  • Font size
  • Print
  • 1 comment

Information security may be improving but embarrassing incidents involving data loss or identity theft at the Veterans' Administration and at TJX Companies, the operator of T.J. Maxx and Marshalls retail chains, suggest that the battle is a long way from victory.

Indeed, three-fourths of the information security professionals around the world surveyed by Frost & Sullivan say they now consider avoiding reputation damage to their organizations as a top priority.

That fits with the times. Increasingly, companies are elevating the prevention of high-profile data security breaches to the level of a strategic goal, if not competitive weapon.

Here's where things are getting interesting. That new sensitivity to data loss has invited more high-level scrutiny from the business side into how IT maps out its cyberdefenses. In fact, the percentage of information security personnel reporting to executive management or boards of director has climbed to 49 percent from 21 percent just four years ago.

"Information security professionals are under increasing pressure to secure not just the perimeter of the organization but all the data and employees that belong to the organization," according to the report, which was conducted at the behest of the International Information Systems Security Certification Consortium.

"We're seeing a shift toward a more information-centric approach...where will need to take security consciousness beyond IT to every person in the organization," said Howard Schmidt, the president of R&H Security Consulting. "Time is clearly of the essence and we have to rethink our approach to security,"

The survey included responses from 7,548 information security experts in various geographies. Among its other conclusions:

51 percent of respondents say that internal employees pose the biggest security threat.

75 percent of respondents see viruses and Internet work attacks as top or high threats. Next in line as a security concern came hackers and employees.

Cyberterrorism remains more of a concern for government than for people working in other sectors.

The most concern voiced about all security threats came from the banking/insurance/finance sector.

The report also suggested a good news-bad news paradox: Even as the economy slows, security concerns should contribute to strong demand for products and services that help IT prevent data breaches. The report also said that regulatory compliance will also factor into the equation, feeding demand for more information security professionals.

Charles Cooper has covered technology and business for more than 25 years. Before joining CNET News, he worked at the Associated Press, Computer & Software News, Computer Shopper, PC Week, and ZDNet. E-mail Charlie.
Recent posts from Coop's Corner
It's Coop's -30- column: Adios, sorta
To catch a (cyber) thief: It's not easy
I'm officially dropping out of the Twitter gab fest
Telcos said testing plan to offer PCs to businesses
The world is flat. So what's our problem?
First GM, now Silicon Graphics. Lessons learned?
LotusLive Engage: IBM's cloud gets social
LongJump to foster private clouds for corporate IT
Add a Comment (Log in or register)
by bluemist9999 April 22, 2008 5:38 AM PDT
In the end, good information security relies on many things. Partly relies on good computer security---itself an enormous challenge. That, itself, is a multi-layered approach comprised of operating system updates, firewalls, antivirus scans, and system hardening.

But, by itself, good computer security is far from the last word. If I have a computer configured like Ford Knox, but send its information via smoke signal to another secure system, my information isn't secure.

Finally, the people working for the company are a key component. Many hacks are social engineering --- the hackers pretend to be working for the company and gain privileged information which they then use to compromise security.

So it's an enormous task. I'm glad there is more scrutiny, but it'll take a long time to make a significant impact.
Reply to this comment
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Coop's Corner

Charles Cooper has covered technology and business for more than 25 years. A graduate of Queens College and Columbia University, Cooper received the Excellence in Journalism award from the Northern California branch of the Society for Professional Journalists for column writing.

Add this feed to your online news reader

Coop's Corner topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right