13 Apr 2006
Organisations should develop two-way authentication methods to deal with the problems of identity theft and electronic fraud, according to CA security expert Simon Perry.
Perry, who is CA’s vice-president of security in Europe, the Middle East and Africa, said current authentication techniques are usually one-way - allowing organisations to confirm the identify of users but not helping users to confirm the identity of organisations.
Perry argued that to tackle problems such as phishing scams, firms now need to develop two-way identification systems, so individuals can verify the identity of organizations. This would prevent scammers from posing as trusted third parties, such as banks, to elicit sensitive data from users.
“With the rise of online banking and ATMs, there’s no guarantee for the individual to prove it’s their bank, as they’re not actually walking into a high street branch,” Perry said. “Until organisations go back and rethink the model, they won’t solve the problems with strong authentication as it’s still based on one-way.”
Perry added that he seed little opportunity at present for combined identity management systems to control access to buildings and IT systems. “When you explain the nitty-gritty details of what it would mean, firms aren’t so happy,” he added. “For very secure premises, it’s a great idea. But it’s not good right now for the mainstream.”
Meanwhile, CA is focusing on building services around its existing product lines. “We’re not likely to make any big acquisitions in line with the size of Netegrity. The building blocks are in place now, so our strategy is focused on those and on executing our existing EITM [Enterprise IT Management] plans,” he said. “We’re going to be building capabilities into our products for roles discovery and process management and services to go with that.”
The vendor aims to develop and promote a range of pre-deployment consultancy services, targeting existing customers with whom it already has trusted relationships. To support these efforts, CA will build up a consulting division that will operate under the existing corporate brand. “We’re moving from selling a piece of software to having a long-term relationship with certain customers,” Perry added.
Perry added that customers need reassurance that CA’s services will not be biased. “If we give the impression that all advice leads to CA [solutions], they’ll chuck it back,” he said. “We can offer ways of how CA might solve problems, but we’re not trying to be a systems integrator.”
Have your say on this article
Newsletters
Latest stories from Security Technology
Latest videos
You may also like
Security Technology jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?