Firms must do more to prevent ID theft

A recent DTI survey has identified holes in most firms’ data protection and management systems

Written by Phil Muncaster

Almost 100 percent of UK firms do not have sufficient identity and access management safeguards to prevent electronic ID theft, according to the 2006 DTI Information Security Breaches Survey released today.

Just one percent of UK companies had all the correct measures in place, and nearly a fifth of large companies reported that staff had gained unauthorised access to data.

"The figure is so high [because] there are so many different things organisations need to do [to secure access to their systems], and it will take them a long time to build up their foundations," said Andy Kellett of analyst firm Butler Group.

Kellett added that the required management systems vary according to the sector in which firms operate. For example, a system combining controls for physical and network access would be particularly relevant to manufacturing and retail environments.

Andrew Beard from PricewaterhouseCoopers, who lead the survey, said few companies are strengthening and integrating their authentication, provisioning and authorisation systems because most companies simply respond to regulations imposed on them.

"Firms are being reactive rather than proactive," Beard said. "It's a small comfort that [identity management problems in the latest survey] were not much worse than they were in 2004, but although the incidents are relatively low, when they do happen they have more impact."

The risk bad publicity in particular means organisations cannot afford to neglect identity and access management, Beard added.

John McNulty, chief executive of security specialist Secure Computing, predicted that sales of authentication and identity management tools will grow rapidly as more firms realise the importance of a comprehensive IT security strategy.

"We've been preaching for the last six years that security should start from knowing who the user is," McNulty said. "The strength of authentication – from fixed passwords all the way to two-factor authentication – should be appropriate to the value and sensitivity of what you're gaining access to."

Donal Casey of IT consultancy Morse said, “Businesses need to wake up and take some action. It’s ludicrous that businesses are relying on passwords alone to protect their data. Businesses must make sure that they firstly put in place a range of measures to protect against things like identity theft, but secondly that they make sure all these measures are integrated so that there aren’t any holes for hackers to exploit."

The full results of the survey will be released at the InfoSecurity Europe event in London in April.

Tags:

reader comments

related articles

Bank strikes back at ID cheats

All A&L online bankers issued with two-factor authentication 16 Mar 2006

 

Business holds key to ID card success

Director of the UK ID card programme says that banking sector leads calls for cards 23 Feb 2006

Phishers catch eBay users again

Emails masquerade as eBay portal queries 06 Jan 2006

Fraud costing Scottish business £1bn a year

Cases going through the courts are just tip of the iceberg 16 Feb 2006

Google launches security apps

New range of Google Apps could boost the web giant's reputation among large enterprises 05 Feb 2008

Google launches security apps

New range of Google Apps could boost the web giant's reputation among large enterprises 05 Feb 2008

Review 2007: IT security and e-crime

Computing's review of the year looks back at the top IT security and cybercrime stories 20 Dec 2007

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Examining the IT skills challenge

Watch a BCS roundtable debate on the issues affecting IT professionals - the last of a four-part series 17 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Has the state of the economy forced to re-evaluate your IT purchasing options?

Has the state of the economy forced to re-evaluate your IT purchasing options?

Are you re-thinking your IT spending?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Soca unitAnalysis

EU police in the dock over data sharing

Poor integration and lax practices are jeopardising EU efforts to fight international crime 20 Nov 2008

Advertisement

Primary Navigation