Firms failing on data sharing

Firms are acting to secure sensitive data, but third party risks remain

Written by Phil Muncaster

Over half of organisations are failing to manage the risks of sharing data with third parties, although many are now investing in securing the capture and storage of sensitive data, according to a new global survey by consultancy Ernst & Young.

The firm's Global Information Security survey of 1,200 public- and private-sector organisations in nearly 50 countries found that more than three-quarters cited privacy and data protection as a significant issue, with 52 percent addressing privacy and data protection with formal procedures.

"It's been an issue for years but it has been done in an ad-hoc way through point solutions," explained the firm's UK head of Technology and Security Risk Services, Richard Brown. "What's caused that is a combination of consumers being more savvy in that area, and organisations getting on top of segregation of duties and securing data."

He added that although many firms are now taking "a good solid risk management approach" to data security, it is becomingly increasingly important to have disaster-recovery processes underpinning that. But only half of respondents said they actually tested their plans while only 46 percent said they have communication strategies in place.

Another major finding of the survey was the lack of formal agreements with third-party suppliers for secure data-sharing in just over half of firms. Brown argued that this is because contracts are often set up without the input of the CIO, who should enforce compliance with corporate standards over data security.

Donald Massaro, chief executive of secure messaging specialist Sendmail, agreed that firms are now taking data security a lot more seriously, driven by compliance to new legislation and high-profile data breaches.

"It has reached a tipping point in the States and the Californian [data breach notification] law has put some teeth on it," he explained. "Also, losing intellectual property is a violation of Sarbanes Oxley; it's all high visibility stuff that has the attention of [C-level executives] and it's moving over into Europe."

Tags:

reader comments

related articles

System revs data recovery

SANSymphony 'Traveller' CDP solution hopes to help sites recover from attacks. 06 Nov 2006

 

Data privacy in spotlight after European ruling on flight data

A new deal is needed to allow EU states to provide passenger information to the US 01 Jun 2006

Indian data breach hits HSBC

Insider fraud at HSBC’s Indian site underscores the need for security that extends to offshore locations 28 Jun 2006

Semantic web threatens data privacy

There may be teething problems ahead, but also major benefits for businesses 13 Jun 2006

Interview: Consumers protect data with Garlik

Tom Ilube of privacy firm Garlik argues that firms must give users more control over personal data 09 Nov 2006

How data rules will burden business

The EU's Data Retention Directive poses a major technological and managerial challenge 06 Oct 2006

Privacy tzar speaks out against data breach notification laws

But Information Commissioner admits breach levels remain worrying 29 Oct 2008

Information Commissioner says database threatens way of life

Calls for public debate about Government plans 16 Jul 2008

Legislators under fire over heavy-handed security rules

Firms being forced to spend unnecessarily on perceived IT security risks, say experts at RSA show 27 Oct 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation