NEWS Companies are still leaving themselves exposed to security breaches by focusing on technology and not policies, according to a survey of major public and private sector users. The third annual 'Information Security in the UK 2003' survey by consultancy Detica quizzed 140 FTSE 500 companies and major public sector organisations. It found awareness of formal security procedures within companies has dropped from 82 per cent last year to 54 per cent this year. And 40 per cent said security investment is focused on technology, compared to 35 per cent who said it goes on policy. David Porter, head of security and risk at Detica, told silicon.com that although internal and external threats both pose as much of a headache, resources are disproportionately spent on things like firewalls in an attempt to shore up the perimeter of the network. "There's probably an equivalent threat on both sides but most resources are being spent on the external threat. They often take a prevention-centric approach pumping money into things like firewalls but what that won't do is keep out the insider threat." On a brighter note for the public sector, the survey shows it is taking a better approach to IT security, with the commercial sector looking more to short-term ad hoc solutions as opposed to a strategic view. Porter said: "The private sector seems to think that by buying technology they can tick the compliance box but technology is just there to implement procedures." Awareness of the security standard BS7799 has dropped significantly with just two per cent of respondents looking for accreditation this year, while 57 per cent of IT directors are not even aware of it. Porter said the cull of middle management in numerous firms through the 1990s had removed many checks and balances that allowed employees to perpetrate fraud by electronic means. Helpdesk staff, in particular, he said had access to lots of high-value information in various systems.
Insider threat still leaving companies exposed
Firms spending too much on security technology, says research…
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Detection systems guard against network intrusion
How do the different types of intrusion prevention system (IPS) work? Inline systems sit on the network like layer-two...
-
How malware threats have changed
These days, cybercriminals have four core weapons: targeted attacks, infecting websites, social networking and mobile...
-
Guide to social media use in your business
Are you on Twitter, Facebook or Google ? Even if you're not, you should know about social networking's benefits and...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





