
Don't trust it to your techies alone, they're doing you no favours...
Published: 15 September 2005 08:35 GMT
Analyst house Gartner has hit out at companies who are allowing their techies to dictate how the organisation secures itself and has called upon businesses to mature and embrace strategic rather than technical thinking.
Speaking at the annual Gartner IT Security Summit, Jay Heiser, research VP, said the fundamental problem with a purely technical approach is that IT security professionals have no understanding of the business.
He said businesses must now mature and appoint individuals who understand the complexities of business, rather than the simplicities of security.
Heiser said a 'risk management officer' is now more critical than the traditional security professional whose job is either a part-time distraction from network management, or latterly to "scare money out of the CIO" or block projects which could have proven beneficial to the organisation.
Heiser said: "You can take somebody straight out of college and they can manage your firewall", urging businesses to get on with the more important task of understanding their risk and their priorities.
One company which certainly understands risk and has adopted the approach of using business-focused managers in senior security-focused roles is insurance giant Zurich.
Stefan Vogt, head of group IT risk at Zurich, told delegates his organisation has outsourced the commodity aspects of IT and security, such as firewall and user provisioning, in favour of concentrating on more strategic issues.
He said: "We don't consider managing the firewall to be our day-to-day job. We don't have people doing that within our organisation. We are now working on a strategic level."
"It has gone away from being reactive to being proactive and looking to see what might go on," added Vogt who said policy now tops his list of priorities, while the firewall is at the very bottom.
Adopting this approach has contributed to a halving of annual IT spend at Zurich from nearly $2bn to "closer to $1bn", said Vogt. And, by recognising risk early, rather than fighting threats reactively, Heiser argues there is also a large return on investment.
Heiser said no two companies are the same and fire-fighting and throwing money at all emerging threats may not be relevant. Companies who spend excessively on securing the perimeter, for example, may not have realised the greatest risk to their business is posed by the loss of intellectual property from within, as staff ferry portable devices in and out of the company unchecked.
Companies must therefore look beyond the obvious technical solutions, said Heiser, and understand both operational risk and acceptable risk.
But tradition techies "are people for whom acceptable risk is an oxymoron", he added.
"If you're going to make profit you have to have risk. Taking risks is part of making a better business."
"Stop being so technical and allow the business to become totally integrated with security," said Heiser, arguing that companies who continue to throw money at their IT department are living in "blissful ignorance" as far as the wisdom of their investment is concerned.
The ideal candidate for bridging this gulf, he said, will have communication skills and project management skills; probably with a business school background majoring in risk management.
But he believes there is little hope of technically minded individuals making the leap into this new middle-ground from within the IT department without them also having a rare understanding of the bigger business picture.
Paul Proctor, a Gartner VP, added that regulatory pressures have already gone some way to forcing this change as companies realise the IT department, though involved in the process of compliance, is ill-equipped to understand the wider business ramifications.
Stop the press where have I heard that comment bef...
John Hall
It never was just a technical issue, as any real s...
Anonymous
And yet another outsourcing scheme has been offere...
Anonymous
I agree. But then again...when was security NOT j...
Lando
Hmm, I bet if we looked at the service contract th...
anonymous too
Core areas include but are not limited to: * Hazard identification * Qualitative and quantitative risk assessment * Fire and explosion engineering * ...
ITIL/BS15000 change control processes * Ability to reach & maintain a high level of UK Government security clearance * Excellent system design ...
Providing front line support for all information security related issues, such as firewall configuration, managing SSL Certificates, advising on ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...