You are here: silicon.com > Software > Security Strategy

Security Strategy

Businesses must do better on tech risk

It's a worrying trend, says KPMG...

Tags: research, audit, risk

By Tim Ferguson

Published: 21 September 2007 15:45 GMT

A significant proportion of corporate audit departments are failing to address IT risk sufficiently, leaving businesses vulnerable and open to security threats.

Almost a third (30 per cent) of audit staff feel their audit committee doesn't spend enough time looking at IT risk, according to research by KPMG's Audit Committee Institute (ACI).

Read all about IT…

Check out the Editor's Blog for the silicon.com chief's take on the hot tech issues of the moment.

Half said they don't have oversight responsibility for business continuity, and more than half (55 per cent) said they don't have responsibility for auditing risk around information security and privacy.

Around one in five (21 per cent) said they don't have responsibility for any IT compliance or control issues.

In general, the survey showed nine out of 10 audit committee members feel at least some improvements need to be made with their oversight of IT risk issues.

Director of KPMG's ACI in the UK, Tim Copnell, said this is a worrying trend due to businesses' reliance on IT.

He added that if audit committees aren't paying sufficient attention to the IT risk then businesses could be unwittingly exposed.

Instead of IT, the top priorities for audit committee members are more general risk management, internal controls and accounting judgements.

The ACI survey covered 1,300 audit committee members in 25 countries.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Disaster Recovery Specialist / Business Continuity Manager

Disaster Recovery Specialist / Business Continuity Manager urgently sought by a major organisation based in their prestigious offices in South ...

Director of EU Order Management (location in Brno, CZ)

As such, this position has a direct impact on the successful operations of the organization.Essential Functions: Functions that this role will ...

Information Security Consultant - URGENT

In addition to this you will also be expected to provide expertise and support in operational risk, governance, business continuity, data leakage and ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: