Experts see era of insecurity

Inadequate laws, insufficient defences, complacent ISPs, flawed software, and evolving spam and viruses mean trouble ahead

Written by Madeline Bennett & Dinah Greek

IT leaders, government officials, security vendors and analysts at the recent Infosecurity Europe event heard that firms are facing growing threats to their systems.

Delegates were told that the number of malicious attacks has been rising, and is expected to grow further over the next year.

The DTI published its Information Security Breaches Survey 2004, with figures that indicate many firms are still not giving security the attention and resources it deserves. Over half of firms spent just one percent or less of their IT budgets on security last year; and very few were taking steps to estimate the value of their security expenditure.

Security standards and certifications were widely ignored, despite being promoted by the government and security vendors. Almost two thirds of large UK organisations were unaware of the contents of the British security standard, BS7799. And three quarters of those responsible for IT security in large enterprises did not have any formal security qualifications.

Firms were advised not to assume that developers of software and systems would provide safe products free from vulnerabilities. "Security is an afterthought as it always has been and always will continue to be," warned Fred Cohen, principal analyst at research firm Burton Group. "Application and operating system security is the root problem. Developers are just not doing their jobs well and convenience is still winning out over security in many cases."

Stephen Timms, minister of state for e-commerce, added, "Information security problems are a routine part of everyday business life. All of us have to roll up our sleeves and deal with them."

Spam, though traditionally not viewed as an IT security issue, was high on the show's agenda. "Spam and viruses are converging, and are becoming one and the same attacks," said Cohen.

Delegates were told that spam is unlikely to be stopped by European and US anti-spam laws. Email security firm MessageLabs said that new laws had not reduced the amount of spam sent and could in fact be making matters worse.

MessageLabs' chief technology officer, Mark Sunner, said the US Can Spam law and the EU Privacy and Electronic Communications Directive had created confusion and gave companies a false sense of security. "These laws are probably creating more problems than they are solving," he argued. "We can show the legislation is not working because we have collated the data and are seeing the growth rates in spam since they were introduced."

Sunner argued that the Can Spam Act has a major shortcoming. "It assumes spammers are scrupulous and will abide by the law," he said. "The EU directive is confused and is being interpreted in different ways by each member state."

Jean-Jacques Sahel, deputy head of e-communications policy at the DTI, said harmonisation of global anti-spam legislation was needed, but he defended the EU privacy law. "There are slight differences in national laws [in EU member states] but overall the directive is quite solid in the way it is implemented across the EU," he said.

Sahel said that the DTI would put information on its web site by the end of May to show how countries were interpreting and implementing the directive.

Sunner added that ISPs could do more to protect end users. "If the water that came out of your taps was filthy and you had to filter it you wouldn't be very happy," Sunner said. "ISPs are basically giving us the equivalent of sewage. If they installed protection at the internet gateway this problem could virtually disappear."

Tags:

reader comments

related articles

Prolific US spammers

US blamed for 85 per cent of spam

Can-Spam law having little effect on US junk mailers 18 Aug 2004

 

Worried firms consider email boycott

Security concerns threaten future of 'everyone's favourite killer app' 16 Jul 2004

Patching gap gets narrower

The grace period between patch release and the first wave of attacks is disappearing fast, experts warn 02 May 2004

Vendors feel security heat

IT buyers are putting growing pressure on vendors to improve security 26 Apr 2004

Children ignoring online dangers

Apathy remains the biggest concern 14 Feb 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation