Home > Security News > Companies fear dark corners of the virtual world
Security News:
EMAIL THIS

Companies fear dark corners of the virtual world

By Bill Brenner, Senior News Writer
14 Mar 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The dark alleys of cyberspace have become as real as those in the physical world, and probably more dangerous. That's the perception of about 600 U.S. IT professionals IBM surveyed in December and January.

Stuart McIrvine, IBM's director of corporate security strategy, said more than ever before businesses and consumers understand that cybercrime is at least as dangerous as physical crime.

"They also see cybercrime as a battle they can't fight on their own," McIrvine said. "They believe businesses, technology providers and law enforcement must work together on the right safeguards."

Nearly 60% of respondents said cybercrime could cost their companies more than physical crime, IBM found. Those polled expressed concern that online attacks could cost their companies in revenue, customers and worker productivity. Eighty-four percent said organized, tech-savvy criminal groups are replacing lone hackers as the biggest threat. Three-quarters of those surveyed believe unprotected systems located in developing countries are adding to the overall threat.

More on recent surveys

IT pros: We can't stop every threat

Report suggests security practices lag behind requirements

IM threats grow, response lags

FTC promotes ID theft awareness

Meanwhile, 74% said threats to corporate security are now coming from inside the organization. But McIrvine said respondents don't seem to be taking adequate steps to deal with that.

"When you ask about what [respondents'] priorities are, they still talk about perimeter protection," he said. While perimeter protection is necessary to blunt attempted hackings and malware attacks coming from the outside, it won't help against cyberattacks coming from the inside, he added.

Eighty-three percent of respondents expressed confidence that they're protecting their enterprise by upgrading their AV software (73%), upgrading their firewall (69%); implementing intrusion detection/prevention technologies (66%); and putting a vulnerability/patch management system on the network (53%).

Asked what their two most important security priorities are for the next year, 39% said upgrading their AV software and 32% said upgrading their firewall.

McIrvine said IT professionals can't defend against the evolving threats of the digital age if most of their attention is on the AV and firewall -- especially if they have any hope of countering the insider threats. To that end, IT shops need to put more emphasis on who their users are and tightening data and systems access rules.

"There always has to be a balance between the user-centric view and the data-centric view," he said. "The user centric view looks at who's the user, what roles exist and how should user groups be put together. The data centric view looks at what data a company has and what information needs to be classified."

Based on these classes, he said, "You need to perform risk management to decide what your core priorities are and what kinds of protection you need."

The survey results indicate that IT executives in the finance sector are more concerned about cybercrime versus physical crime: 50% cited it as a bigger threat vs. 38% of the total surveyed. Respondents from the finance sector also expressed more concern about the cost impact of cybercrime than IT executives in other industries -- 71% vs. 57%.

Cybercrime also outweighed physical crime for respondents in the healthcare and manufacturing sectors. Respondents in the retail sector still see physical crime as the biggest threat, however.

The results also indicate respondents in the healthcare and finance sector are more worried about losing prospective customers than those in the retail and manufacturing sectors. Manufacturing respondents view damage to brand/reputation as far more of a concern (52%) than in the healthcare (40%), financial (35%) and retail (32%) segments.

Tags: Enterprise Risk Management: Metrics and AssessmentsSecurity Awareness Training and Internal ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Enterprise Risk Management: Metrics and Assessments
How to justify information security spending on cloud computing
Layoffs prompt insider threat fears, cybersecurity survey finds
How to avoid Internet liability lawsuits
Bruce Jones: Report Security and Risk Metrics in a Business-Friendly Way
Bernie Rominski: Communicate Effectively with Management about Risk
Best Policy and Risk Management Products
Monitoring program data and internal controls for risk management
Risk management strategy for an information technology solution provider
Align your data protection efforts with GRC
The basics of enterprise GRC project management
Enterprise Risk Management: Metrics and Assessments Research

Security Awareness Training and Internal Threats
Health Net breach failure of security policy, technology
Health Net healthcare data breach affects1.5 million
Massive T-Mobile UK security breach involves insiders
Secure your remote users in 2010
Layoffs prompt insider threat fears, cybersecurity survey finds
How to use Internet security threat reports
Creating a HIPAA employee training program
Successful rogue antivirus hinges on social engineering
External attacks start with unintentional mistakes, survey finds
Security technologies fail to address insider threat management

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
dumpster diving  (SearchSecurity.com)
Honeynet Project  (SearchSecurity.com)
insider threat  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
pretexting  (SearchCIO.com)
shoulder surfing  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
social engineering  (SearchSecurity.com)
Total Information Awareness  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts