iTnews
  • Home
  • News
  • Technology
  • Security

Security professionals aim to end data breaches

By Phil Muncaster
Apr 28 2008 11:58AM
Follow google news

Preventing data breaches is the highest priority for today’s IT security professionals, two new surveys have concluded.


But delegates at the Infosecurity Europe show in London last week were divided on the most effective method for securing data – and protecting corporate reputations.

The Department for Business Enterprise and Regulatory Reform (Berr’s) biennial security survey showed 77 percent of firms now regard protecting customer information as a priority. Yet only eight per cent of those polled encrypt data stored on laptops.

Meanwhile, in an ISC2 Global Information Security Workforce Study of more than 7,500 security professionals, avoiding damage to reputation was a priority for 71 percent of respondents. A further 70 percent said protecting customer data was a priority, while 61 per cent said the risk of breaching laws and regulations was a driver for information security governance.

But the disparity between firms’ security intentions and their actions persists, argued Chris Potter, a partner at PricewaterhouseCoopers. “There are gaps between the aspirations of companies and what they are actually putting into practice,” he added.

The lack of dedicated IT security professionals and the ever-evolving nature of threats are major factors adding to the risks that firms face today, argued Potter. Companies should step up their risk assessment programmes, he advised.

But Information Commissioner Richard Thomas, told delegates he believed firms’ reluctance to take data protection seriously would persist until stronger penalties were enforced. He noted that while high-profile cases such as the loss of millions of personal records by HM Revenue & Customs had raised awareness, the attitude of the public sector towards data protection remained “worrying”.

Thomas said he was frustrated that powers to imprison those convicted of il legally trading information had yet to be fully enacted. “I’m still seeking serious deterrents to those who engage in this illegal market,” he advised.

Further evidence of government heel-dragging was perceptible in one of the big holes in the show agenda. The Police Central E-crime unit had been expected to be operational in time to unveil its new e-crime reporting portal at the show. But a spokeswoman for the Association of Police Officers confirmed that launch plans have been pushed back.

Some security experts believe that business leaders will not take data loss prevention seriously until they are compelled to inform customers of any breach.

Howard Schmidt, director at security company Fortify, and one-time security adviser to the White House, insisted that breach notification laws had been largely successful where they had been introduced.

“Breach notifications would be of benefit to anyone. But when you have the requirement to do so, it must be consistent. In the US, states make their own [laws] and there is a lot of complexity. This makes it difficult to manage,” he suggested.

Meanwhile, other security experts bemoaned the general level of organisational security awareness.

“What we find is that we may have got the technical problems solved but we need to raise the human element,” said Martin Smith of The Security Company.

Although firms are trusting their staff more by reducing blocks on instant messaging and opening up internet access, training policies still lack vigour, the Berr report found.

But Mike Smart of security vendor Secure Computing argued that technology controls are an important part of an effective security risk management programme. “Policy-based actions, like encrypting content, become very important and technology can help to stop users clicking on a certain link, to [mitigate the risk] from social engineering attacks,” Smart explained.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:
aimbreachesdataendprofessionalssecurityto

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

AI is delivering business value today
Partner Content AI is delivering business value today
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.