Jonathan Penn
Penn: Security chiefs are constantly thwarted by a lack of budget

Security chiefs need to influence

Protecting your organisation is about understanding the business and winning over executives

Written by Jonathan Penn

As industry watchers, analysts identify and understand trends. And for six years at Forrester Research, we have been talking about the shift from IT security to information risk management (IRM).

The market has embraced the IRM concept and adopted the terminology to describe a movement from the tactical and technical to the strategic- and business value-oriented.

But how far have security managers progressed with the transition? Measuring such progress is precisely what Forrester set out to do in our 2007 security survey of more than 2,000 North American and European firms.

Chief information security officers (CISOs) now understand that their priorities need to align with business objectives. And topping the list of priorities is protection of the organisation’s information assets.

As many as 81 per cent of firms cite protection of customer data as their most important business objective.

CISOs rank business continuity and disaster recovery second, with protection of corporate intellectual property and other sensitive internal data third.
Despite talk about compliance as a driver for security purchases, it ranks only fourth on the list of priorities.

Such findings correspond with Forrester’s analysis of security leaders’ top issues for the next 12 months.

Data security and mobile security rank first, business continuity is placed second and regulatory compliance comes seventh.

Vulnerability and threat management ­ the mainstay of IT security that centres on stopping the bad guys ­ was also towards the bottom of the list. Security teams are instead trying to focus more on what matters to business.

And business executives realise security matters to them.

Of course, business awareness has also been raised by a never-ending stream of breach-instigated stories and lawsuits.

Almost two-thirds of IT security managers now have some degree of reporting, direct or dotted line, outside of IT.

Finance is the key department, but many security chiefs report to legal, human resources or an enterprise risk group.

Some CISOs even report to the executive office, with 20 per cent of European companies requiring direct reporting ­ twice the level of North American companies.
But all is not well. A recurring concern we hear from CISOs is that they are prevented from achieving goals because of a lack of resources.

Security chiefs are constantly thwarted by a lack of budget, shortage of people with the right skills, too many items on their plate, and a lack of influence with executives.

Such issues arise because security teams still hold responsibility for nuts-and-bolts issues, including infrastructure security, identity management and threat management. And managing the basics creates a self-sustaining barrier to success.
CISOs need to gain influence ­ and the key is closer alignment with the business and an appreciation of executives’ concerns.

Jonathan Penn is research director of security and risk management at Forrester Research.

Free Forrester reports are available to Computing readers at www.forrester.com/computingUK

Penn is speaking at Forrester’s European Security Forum, taking place in Amsterdam. For more details visit www.forrester.com/security200

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Picture of a barbed wire fence

Safe from harm

In the first of our four-part weekly guide to security, we looks at the precautions companies should take 03 Apr 2008

 

The next big thing in outsourcing?

Gone are the days when management was simple. Outsourcing now breeds new ideas that just complicate things, says Mark Samuels 21 Feb 2008

Activist sourcing is the future

A new approach will streamline service management and ensure no money is wasted, says Andrew Parker 14 Feb 2008

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation