iTnews

Boards need to pay the cost

By Peter Stephenson,CeRNS, on May 9, 2006 4:23PM
Boards need to pay the cost

In our organisations, we need to take a strong lead in many areas. The first is awareness. I remember a commercial where a smirking executive tells an IT engineer that he just opened an email attachment – like he was told not to. We know that sort of thing happens somewhere in our organisations.

Second is policy. It amazes me how many organisations still don't have a competent security policy. There is no way that we can secure the network without some roadmaps. These are our policies.

Finally, there are tools. If organisations lack strong awareness at all levels, and appropriate policies from which to derive such things as access control, need-to-know versus need-to-share, security tools won't help much.

Unfortunately, the cost is increasing. It's high if we implement the three security areas and even higher if we don't. That cost goes beyond the security budget. In the US, it could be heavy personal fines for the boss or even prison.

As it happens, awareness and policy are minimal costs. Our challenge is getting that point across. We often get lip service without real support, and see the "tick-in-the-box" syndrome where the organisation undergoes the minimum preparation for an audit.

The idea is if all the audit checklist boxes are ticked off, there's no upstream liability, as when someone is hired just long enough to produce the Sarbanes-Oxley documentation a company needs, which I have seen happen. This is so short-sighted. What happens if the worst occurs and, as a result of shoddy security, huge, expensive data loss occurs? It's all part of the cost and we must pay it. And that message needs to be delivered to the boardroom.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
boardscostneedpaysecuritytheto

Partner Content

"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
Don't miss Australia’s premiere IoT Conference on 9th June
Promoted Content Don't miss Australia’s premiere IoT Conference on 9th June
Operationalising net zero to be centre stage at IoT Impact conference
Partner Content Operationalising net zero to be centre stage at IoT Impact conference
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Peter Stephenson,CeRNS,
May 9 2006
4:23PM
0 Comments

Related Articles

  • PEXA buys into AI fintech Elula
  • WA gov creates cyber security uplift team
  • Healthscope CISO heads to KPMG
  • Edtech vendors invaded student privacy: Human Rights Watch
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

What to expect from the incoming Labor government

What to expect from the incoming Labor government

Digital Nation

CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.