iTnews
  • Home
  • News
  • Technology
  • Security

Security gurus laud process benefits

By Phil Muncaster
Apr 4 2008 4:01PM
Follow google news

Information risk experts at a leading IT security conference have underlined the importance of people and processes in delivering an effective enterprise security programme.

Security gurus laud process benefits
Speaking at the annual Forrester Security Forum in Europe, Stephen Bonner, Barclay's head of information risk, insisted that a pre-occupation with technology was undermining security efforts.

Bonner explained that focusing solely on technology solutions will not solve the underlying security problems that plague many firms, many of which are a result of "poorly designed processes".

"A lot of vendors are making a lot of noise around data leak prevention products but I remain unconvinced," he argued. "These are technology solutions to particular problems – you can manage this problem by tying down your email, or USB stick use, but people will just print out material or move [to other methods]."

Several other speakers at the conference also argued that a risk management strategy that addressed IT issues would secure corporate networks far more effectively that concentrating on specific incidents or technologies. " Technology should not take up most of your time; it's just a small layer between the processes and people," said Forrester analyst Thomas Raschke.

Bonner explained that Barclays is running a comprehensive awareness-raising campaign in an attempt to change corporate culture and mitigate the risks associated with the "insider threat".

The firm has commissioned a series of short, accessible videos to raise staff awareness about issues such as device loss, he added.

"Lots of control functions are seen as stuffy, an extra layer of cost and inconvenience, so we're trying to challenge their preconceptions," said Bonner. "And because the awareness material is not mandatory, it makes it a bit more viral, drawing attention to the issues."

Bonner argued that in 80 per cent of incidents involving insiders, the perpetrator exhibited unusual behaviour beforehand. "Most of the issues can be resolved not through technology … but by walking towards the problem," he said, "If someone in the team is known as a bit dodgy just have a word – in a lot of cases something was known to be wrong and no-one did anything."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:
benefitsprocesssecurity

Related Articles

  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
Join our WhatsApp Channel

Partner Content

The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.