On The Insider: Cougar Town Production Postponed
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner ZDNet UK
Posted on ZDNet News: Jun 22, 2009 10:31:41 AM

IT security has been neglected due to the economic downturn, according to security experts.

Bruce Schneier, BT's chief security technology officer, told a European Network and Information Security Agency (Enisa) event on Friday that organizations are struggling to keep on top of workloads that have increased due to layoffs.

"Times are tough, even for criminals," said Schneier. "Organizations are dealing with more disgruntled employees — the people you are firing. People in organisations are doing a lot more fire-fighting. IT security has fallen by the wayside, because you're not getting something done — it's preventative."

Schneier said that people view IT security, as any business activity, by its results. However, IT security, when it is successful, does not have any tangible results, so people focus on measurable outcomes.

"People view business in terms of what it will do for me today," said Schneier. "When it comes to [activities such as] updating firewall settings, people say 'We'll do that when we have time.'"

This lack of tangible results can lead to security budgets being cut, said Schneier, especially if the IT security capability has been so good it has prevented incidents.

"This happens in IT security all the time," said Schneier. "If you're doing really good, people will say 'We don't need you, because there have been no incidents'. Justification for IT security requires a level of abstraction."

Schneier said that organizations that are reducing their staff levels, for example by 15 percent, would think it right to reduce their security capability by 15 percent. However, Schneier said this reasoning was flawed.

"It seems logical you can reduce security by 15 percent, but it turns out not to be the case," said Schneier. "Because of redundancies, companies are becoming leaner, and IT systems are becoming more critical to the business. I'm seeing security groups being asked to harden systems because they are more business-critical."

Chris Potter, a partner at auditors PwC, said that incidents tend to happen every three to four years, which means people downgrade the risk.

"Over time, risk assessments deteriorate," said Potter. "That window of three to four years is a long time in the corporate memory."

Potter added that organizations that have invested in automating computer processes have been the most resilient through the recession.

"The more organizations have invested in automating where they can, the less they have been affected by the downturn," said Potter. "Organizations that are less mature have been the most affected."

At the same Enisa event on Friday, security experts advised businesses not to clamp down on social media.

This article was originally posted on ZDNet UK.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 1 Talkback(s)
I wish I were surprised  epcraig | 06/23/09

What do you think?

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here