You are here: silicon.com > Software > Security Strategy

Security Strategy

Security: Can you really trust JUST techies?

HR, senior execs and staff all off the hook as IT team take the blame...

Tags: security, antivirus, governance

By Will Sturgeon

Published: 6 September 2004 17:25 BST

UK companies are still failing to recognise the importance of properly implemented and managed security, assuming it is just a 'technology issue' rather than a fundamental part of the way their organisation works.

By passing the buck wholesale to the IT department companies are exposing a number of flaws across their organisation - from the top down - and even a tightening of legislation and increased emphasis on accountability and corporate governance has done little to interest the head-in-the-sand 'higher ups' that they should be getting involved and delegating tasks effectively.

According to independent research conducted by Coleman Parkes on behalf of LogicaCMG, 53 per cent of companies entrust the IT department with the sole enforcement of the information security policy.

In addition, 71 per cent of companies rely on the IT department to implement information security policies and approaches - despite the fact that much of the planning should relate to HR and legal issues as much as to the technology in place.

Dave Martin, principal security consultant at LogicaCMG UK, said IT alone is not enough and "process and policy are central to ensuring information security governance". Invariably the IT department, for a number of reasons, are ill-equipped to issue such policy. Nor they would argue should it be their job.

Sal Viveros, SME director at security giant McAfee, believes one of the biggest obstacles to effectively managing security issues centrally from the IT department is the perception of other employees.

Viveros told silicon.com: "A lot of people tend to think of the IT department as being just the guy who takes an age to fix their PC or tells them what they can and cannot have installed on their machine or what machines they have."

Viveros said as a result those in the IT department are often seen as "the bad guys" and coupled with a perceived lack of seniority within the company this makes it difficult for them to dictate, manage and enforce policy.

While staff may sit up and take notice of a policy handed down by HR or a member of senior management, because the trail of accountability and its direct link to discipline procedures is evident, employees may feel less inclined to treat seriously the requests of the IT department.

There may even be a 'the police have all the best drugs' level of resentment whereby employees being told not to do certain things assume those in the IT department handing out such rules are doubtless breaking them themselves and above such policy.

Companies would certainly do well to treat such issues more seriously. Especially as employees, who are rarely governed by stringent enough policies, are generally regarded as the weakest link in the security chain.

And the risks of making mistakes in this area are huge. In a separate study conducted by MORI, also on behalf of LogicaCMG, 83 per cent of investors said a security breach of any kind would impact that companies' share price and 56 per cent they would sell their shares in the event of a breach. And it's not just investors who would take issue with breaches - according to the research 70 per cent of customers would also 'vote with their feet' - boycotting a website if there was the suggestions its security had been compromised.

The fact companies are seemingly doing little about getting on top of security is made all the more surprising by the fact companies are aware of such risks.

A massive 86 per cent of the FTSE 350 companies researched said negative publicity for their company would be the key impact and a similar number (84 per cent) said their brand would be damaged by a security breach.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
HRS - Operations Support Lead-00055714

Job Purpose To drive and manage the coordination of core activities across EALA which include contract governance, Quality Assurance, Performance ...

Project Manager (Infrastructure Projects): Cheshire 53k

Financial management and control will fall within your remit, as Project Manager, having direct accountability for project budgets of 1-5m. Global ...

Security/Quality Analyst-00055189

Accountability / Responsibility: Security Drive and monitor the security compliance within the organisation. Attend governance meetings. Experience ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: