NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Why Technology Isn't The Answer To Better Security

You've beefed up your IT security arsenal, and you're focused on compliance. But you're still vulnerable. Here's why.

 

October 15, 2008CIO — Not to be alarmist, but WAKE UP, PEOPLE! Our information security is, in many ways, failing.

Ask the 11 alleged hackers charged in August with breaking into TJX and other retailers by way of insecure Wi-Fi. Forty million credit and debit card numbers were stolen. Ask the Medicaid claims processor at the outsourcer EDS. In February she pleaded guilty to stealing Social Security numbers and dates of birth, and selling them for use on fake tax returns. Ask the courier hired by the University of Utah Hospital to take backup tapes to offsite storage. One day in June, he used his own car instead of his company's secured van. The tapes, containing billing data for 2.2 million patients, were stolen from his front seat.

Or you could, as we did, ask 7,097 business and technology executives worldwide about their security troubles. In this, our sixth year of conducting the "Global State of Information Security" survey with PricewaterhouseCoopers, we got an earful about the challenges, worries and wins in security technology, process and personnel.

Quantifying returns on information security projects can be a struggle, often because it's hard to put a dollar value on a crisis averted. This year, a bad economy forces decision makers to squint even harder at proposals. Even so, survey results show companies are buying and applying technology tools, including software for intrusion detection, encryption and identity management, at record levels. That's pretty good news.

However—and this is serious, folks—too many organizations still lack coherent, enforced and forward-thinking security processes, our survey shows. While 59 percent of respondents said they have an "overall information security strategy," that's up just two points from last year and it's not enough, says Mark Lobel, advisory services principal at PricewaterhouseCoopers. Two elements, Lobel says, correlate with lower numbers of security incidents: having a C-level security executive and developing the aforementioned security strategy. But disappointing numbers piled up this year. (For additional stats see "The Global State of Information Security.")

For instance, 56 percent of respondents employ a security executive at the C level, down 4 percent from last year. You comb network logs for fishy activity, but just 43 percent of you audit or monitor user compliance with your security policies (if you have them). This is up 6 percent from 2007, but still "not where we need to be," Lobel says.

As a result, security is still largely reactive, not proactive. More-sophisticated organizations will funnel data from network logs and other monitoring tools into business-intelligence systems to predict and stop security breaches. So along with encryption fanatics and identity management experts, an infosec team needs statisticians and risk analysts to stay ahead of trouble and keep the company name off police blotters.

Loading...
TOOLS
CONNECTIONS
PricewaterhouseCoopers
Brandeis University
 
 
CENTER OF EXCELLENCE
 
Security
» Prudential Financial Protects its Brand with Symantec Data Loss Prevention Solutions
FORTUNE 100 insurance leaders rely on the Symantec Data Loss Prevention solution to protect sensitive customer data.
» Information Security: Data Drains and How to Prevent Loss
Do you know where your confidential data is, where it is going, and how to prevent it from leaving your organization.
» Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands
Learn what the thought-leaders at PricewaterhouseCoopers have to say on the risks associated with data security.
» 7 Requirements of Data Loss Prevention
Incorporate best practices from many companies using DLP solutions as you establish your organization's requirements and safeguard confidential data.
» Ponemon Study: How Much Does a Data Breach "Cost"?
35 U.S. organizations that lost confidential information and had a regulatory requirement to publicly notify affected individuals are studied in this report.
Center sponsored by

 
WHITE PAPERS

War Gaming: Necessary Exercises

Read how Intel approaches war gaming and creates a companywide security force.
 

Mobility is Growing: Survey Shows Why CIOs are Concerned

Although new research reveals sharp increases in mobile computing, driven by the pursuit of a more productive workf...
 

The Case for A Specialized Security Platform

The most robust security systems available today are built on a dedicated purpose-built security platform. In this ...
 

WEBCASTS

IT Disaster: It's Not a Matter of If--It's a Matter of When

Bob Melk, publisher emeritus of CIO magazine, talks with Accenture's Gil Brodnitz about the very real and growing t...
 

Windows Vista: Essential Benefits and Deployment Strategies

Windows Vista is here, but is your business ready for it? Get an update on some of the more practical features of V...
 

Building Competitive Advantage with Next-Generation Wireless Infrastructure

Today's enterprises require a scalable and resilient wireless infrastructure that seamlessly integrates with tradit...
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
IT Jobs
 
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Laptop Security: Where Do CIOs See Weaknesses?

Top 5 Questions to Ask about Server Virtualization

Virtual Storage Best Practices

Server Virtualization Benchmark Results

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: Green Issues for Networking

New IDG Survey Results on Data Center Automation

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Learn what it takes to build a holistic digital collaboration platform

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

White Paper: A Cohesive Network Security Approach

A CISO's Guide to Application Security

Unified Communications & Collaboration: Game-Changing Business Results

New Benchmarks for VMware Among Major Storage Vendors

Virtualization Benchmark and TCO Analysis-Read Now

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

Dramatically boost network capacity and speed-up to 600 Mbps

White Paper: The Roadmap to Data Center Automation

Learn how companies are changing how they reach out to their most profitable customers.

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Mobility is Growing: Survey Shows Why CIOs are Concerned

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions