Nigel Jones
Jones: We have to focus on something achievable

Q&A: Nigel Jones, director of the Cyber Security Knowledge Transfer Network

Innovation, the economics of security, and return on investment are key areas of study for the business-focused group

Written by Phil Muncaster

Nigel Jones is director of the Cyber Security Knowledge Transfer Network (KTN), one of the 24 KTNs set up by the government to encourage the flow of knowledge within communities and between Whitehall and those communities.

Jones talked to Computing about the challenges of encouraging better security.

As director of the cyber security KTN, what are the aims of the organisation?

We are run by the new Technology Strategy Board – an arms-length government board – in fact it's very important that we're arms length and business–focused. We're intended to be the eyes and ears of business, academia and government to advise the Technology and Strategy Board where to invest. We also have a particular mandate to create innovation in the security sector, and to improve security generally.

So what is the value of the KTN's special interest groups (SIGs)?

These are the places where a lot of the thinking gets done. We've just launched one looking at the economics of information security, and previous SIGs included privacy engineering, which resulted in a report launched at the Infosec event. There was also a SIG on secure software development which was set up with the idea that it would produce something people can actually use, like guidelines on the software development lifecycle.

Tell us more about the latest SIG on the economics of IT security?

It will have to focus on something achievable – what are the economic models; is return on investment (ROI) the best way to look at security; what's the relationship between confidentiality, availability and integrity; and can we put values on these to make investment cases?

Unless it's going to be meaningful to business it will be just another useless discussion. And how do we make this thinking on economics available to small businesses who aren't thinking about these things? Another area we could look at is that there is not enough data in this security domain so people are making claims about products which are hard to validate. We also don't know the extent of the attacks on organisations, so we don't know the threat profile of one organisation versus another.

So what is the difference between the way a large organisation approaches security and a smaller firm?

The threat, and people's responsibility about the information assets they hold, is not well understood among small- and medium-sized businesses, and why would it be? So we need to make it meaningful to thes businesses. There are big differences between the way a large financial organisation looks at the problem and how a small business looks at the problem. One sits in a regulatory framework and understands risk and puts a value on its assets and the other may have a responsibility to be PCI compliant but doesn't necessarily value the information it holds.

But giving a monetary value to the information they hold, if not to your business then to the criminal, may work. People also make assumptions about ROI being the only way to talk about security and we need to challenge that.

But how easy is it to affect cultural change?

When people talk about this what they mean is people's behaviour. There's a big focus on information awareness and training but it's much deeper than that – the behavioural aspect must come back into the design element.

This is not a problem that can be solved with some training – more thought needs to go into writing security requirements. I'm not sure you can blame the people for a cultural malaise, if you're not designing systems with them in mind. Education can mitigate poor design or shortcomings but the real work should start much earlier. Our Privacy Engineering Special Interest Group, for example, produced guidance on how to design privacy into all stages of a project, from inception right up to the secure disposal of a product.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

A hard diskPublic Sector

The top 10 public sector data losses - so far

Feeling left out? Don't worry, you're bound to be affected soon 09 Sep 2008

 

E-crime fighters share know-how

UK prosecutors lead the way in setting up data-sharing scheme 04 Sep 2008

General management skills are now as important as technical ability

A selection of leading chief information officers talk about what they see as the most important aspects of the role 28 Aug 2008

Privacy issue will dictate data debate

The government is in a cleft stick over information sharing 10 Jul 2008

IT must lead the privacy debate

We are moving out of the era of techno-fear into one of IT literacy 19 Jun 2008

Infosec 2009: Security must be built in from the start

New initiative aimed at product design stage 29 Apr 2009

How technology is revolutionising spying

Data mining is key to intelligence community, and privacy of personal information cannot be guaranteed, says Sir David Omand 25 Feb 2009

Technology Strategy Board unites knowledge transfer networks

Government-backed innovation bodies to merge 07 Dec 2009

related whitepapers

today's top stories

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

PaperlinX outsources IT and comms to Bull and BT

Paper company spends €22m on five-year deal for desktop management, helpdesk and datacentre services 05 Feb 2010

Social tools take KM to a new level

Technology expert David Tebbutt explains how – and why – organisations should integrate social networking tools into their knowledge management strategy 02 Feb 2010

EDS court defeat puts vendors on their guard

BSkyB’s victory in a long-running court case against EDS has serious implications for the IT industry 02 Feb 2010

Law firm monitors web traffic violations

Bucks declining global security appliance sales with unified threat management (UTM) platform deployment 01 Feb 2010

Advertisement

Security: The New Face of Intrusion Prevention
An outline of traditional IPS functionality, modern developments and how IPS can be deployed easily.

UK businesses’ attitudes to Cloud Computing revealed

Features results from a survey of over 200 Computing readers.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Internet Explorer 6

Internet Explorer 6

Following recent concerns about the security of Internet Explorer 6 are you planning to phase it out?

View poll results

Latest audio and video articles

Tony McAlisterVideo

Video Q&A: Tony McAlister, CTO, Betfair - Part one

On changing the skills development strategy at the online gambling firm - part one of a two-part video interview 05 Nov 2009

Video

Nokia shows upcoming handset technologies

Mobile phone features of tomorrow take the stage 21 Oct 2009

Latest in-depth articles

Analysis

Police hunt for moles with security software

Lancashire Constabulary to monitor data input of 7,000 staff in bid to prevent intelligence leaks 09 Feb 2010

Businessman with eye patch, dagger and tie round head, sitting at laptopFeatures

Are you sure you're not a pirate?

It is alarmingly easy for an IT leader to unwittingly exceed the scope of a software licence, and the chances of being caught out have never been greater, as technology lawyers Mark Weston and Paul Gershlick explain 09 Feb 2010

Primary Navigation