Nigel Jones
Jones: We have to focus on something achievable

Q&A: Nigel Jones, director of the Cyber Security Knowledge Transfer Network

Innovation, the economics of security, and return on investment are key areas of study for the business-focused group

Written by Phil Muncaster

Nigel Jones is director of the Cyber Security Knowledge Transfer Network (KTN), one of the 24 KTNs set up by the government to encourage the flow of knowledge within communities and between Whitehall and those communities.

Jones talked to Computing about the challenges of encouraging better security.

As director of the cyber security KTN, what are the aims of the organisation?

We are run by the new Technology Strategy Board – an arms-length government board – in fact it's very important that we're arms length and business–focused. We're intended to be the eyes and ears of business, academia and government to advise the Technology and Strategy Board where to invest. We also have a particular mandate to create innovation in the security sector, and to improve security generally.

So what is the value of the KTN's special interest groups (SIGs)?

These are the places where a lot of the thinking gets done. We've just launched one looking at the economics of information security, and previous SIGs included privacy engineering, which resulted in a report launched at the Infosec event. There was also a SIG on secure software development which was set up with the idea that it would produce something people can actually use, like guidelines on the software development lifecycle.

Tell us more about the latest SIG on the economics of IT security?

It will have to focus on something achievable – what are the economic models; is return on investment (ROI) the best way to look at security; what's the relationship between confidentiality, availability and integrity; and can we put values on these to make investment cases?

Unless it's going to be meaningful to business it will be just another useless discussion. And how do we make this thinking on economics available to small businesses who aren't thinking about these things? Another area we could look at is that there is not enough data in this security domain so people are making claims about products which are hard to validate. We also don't know the extent of the attacks on organisations, so we don't know the threat profile of one organisation versus another.

So what is the difference between the way a large organisation approaches security and a smaller firm?

The threat, and people's responsibility about the information assets they hold, is not well understood among small- and medium-sized businesses, and why would it be? So we need to make it meaningful to thes businesses. There are big differences between the way a large financial organisation looks at the problem and how a small business looks at the problem. One sits in a regulatory framework and understands risk and puts a value on its assets and the other may have a responsibility to be PCI compliant but doesn't necessarily value the information it holds.

But giving a monetary value to the information they hold, if not to your business then to the criminal, may work. People also make assumptions about ROI being the only way to talk about security and we need to challenge that.

But how easy is it to affect cultural change?

When people talk about this what they mean is people's behaviour. There's a big focus on information awareness and training but it's much deeper than that – the behavioural aspect must come back into the design element.

This is not a problem that can be solved with some training – more thought needs to go into writing security requirements. I'm not sure you can blame the people for a cultural malaise, if you're not designing systems with them in mind. Education can mitigate poor design or shortcomings but the real work should start much earlier. Our Privacy Engineering Special Interest Group, for example, produced guidance on how to design privacy into all stages of a project, from inception right up to the secure disposal of a product.

reader comments

related articles

A hard diskPublic Sector

The top 10 public sector data losses - so far

Feeling left out? Don't worry, you're bound to be affected soon 09 Sep 2008

 

E-crime fighters share know-how

UK prosecutors lead the way in setting up data-sharing scheme 04 Sep 2008

General management skills are now as important as technical ability

A selection of leading chief information officers talk about what they see as the most important aspects of the role 28 Aug 2008

Privacy issue will dictate data debate

The government is in a cleft stick over information sharing 10 Jul 2008

IT must lead the privacy debate

We are moving out of the era of techno-fear into one of IT literacy 19 Jun 2008

Infosec 2009: Security must be built in from the start

New initiative aimed at product design stage 29 Apr 2009

New group to tackle economics of security

Government-backed special interest group will discuss 'wide range of issues' 11 Sep 2008

How technology is revolutionising spying

Data mining is key to intelligence community, and privacy of personal information cannot be guaranteed, says Sir David Omand 25 Feb 2009

related whitepapers

today's top stories

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Government aims to bolster UK's cyber defences

Is the UK’s first national cyber security strategy up to the task of co-ordinating the country’s response to digital threats? Computing investigates 02 Jul 2009

Focus resources on what really matters

IT has become too caught up in the drive for efficiency, at the expense of business success 02 Jul 2009

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation