golden gate bridge

Security lessons from San Francisco

Aligning IT security and business and huge increase in web threats were key topics at RSA show

Written by Gareth Morgan and Phil Muncaster

Aligning IT security projects with business objectives and the huge growth in web threats were the key topics at this week’s RSA security show in San Francisco.

A forthcoming RSA survey will reveal that 80 per cent of firms have not pursued innovations because of IT security concerns.

"The next time a new idea comes up, don't start by saying it isn't secure," said RSA president Art Coviello. "The need to link security to information management and infrastructure is better understood today. But when it comes to security impact on business performance, it's clear we haven't hit our stride.”

Rhonda MacLean, chief global information security officer at Barclays, said that some units within the banking giant had taken the decision to lock down USB ports, to prevent data loss. “That's not an 'enabling' way to think about security in business," she said.

But IT security cannot become more business-focused unless senior management drives the agenda, argued John Thompson, chief executive of Symantec.

“Your information security policy needs to be consistent with how you want to run your business,” he said. “The CFO, COO and everyone else in the executive suite are critical to a culture of security.”

Also at the show, Gene Hodges, chief executive of Websense, advised firms to focus on ensuring that unauthorised agents cannot extract critical data, as efforts to lock down devices, networks and infrastructure have failed to deliver robust safeguards.

Craig Mundie, chief research and strategy officer at Microsoft, argued that technology vendors could also help enhance security through co-operation with rivals. “Ultimately, we need collaboration with other people who are building some parts of the products in the system,” he advised.

Microsoft used the event to launch a beta version of its latest Forefront security system. Codenamed Stirling, the system is designed to reduce total cost of ownership of IT security and provide firms with a more fully integrated suite of products to protect them at client, server and network edge level. A key new feature is Dynamic Response, information-sharing technology that enables the system to respond proactively to threats across the various layers of the IT infrastructure, according to Microsoft.

The US government was also represented at the show. Michael Chertoff, secretary of US Homeland Security, told delegates, “We know that a successful large-scale cyber-attack against our country would have very far-reaching consequences.”

But RSA’s Coviello was critical of government actions, saying regulations aimed at combating IT threats were ill-considered. Much of the current IT security regulation forces companies to spend money on “perceived but not genuine security risks”, he argued.

According to Symantec’s latest research, highlighted at the show, tackling web security threats should be a priority for firms.

The firm’s biannual Internet Security Threat Report, covering July to December 2007, found that phishing hosts – computers that host one or more phishing sites – increased from 32,939 in the first half of 2007 to 87,963 by the end of last year, a 167 per cent jump. The number of site-specific cross-site scripting vulnerabilities also rose from just under 7,000 to more than 11,000 during the same period.

The report also pointed to the growing sophistication of the underground malware economy with credit card details reportedly selling from just 20p each.

Mike Maddison, UK head of security and privacy services at Deloitte, revealed that basic web application vulnerabilities exist in about 80 per cent of the firms the consultancy checks, and warned that development processes needed to be more robust.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

spam image

New spam tricks revealed

Spammers are jumping on legitimate web sites in order to reach unsuspecting victims 11 Apr 2008

 

Symantec acquires app streaming vendor

AppStream set to become the security giant's latest acquisition 10 Apr 2008

Firms being left behind by criminals

Response times are too slow to worry hackers, say experts 10 Apr 2008

Northern Ireland government purchases £6m of new computers to fight data losses

The Northern Ireland Executive is splashing out on new IT kit out to stop data leakages 09 Apr 2008

Microsoft delivers vital patches

Lumension warns of new vulnerabilities 09 Apr 2008

Microsoft ties together security products

Stirling brings together client, server and network security products 09 Apr 2008

Board should be liable for breaches, say security profesionals

Websense survey finds IT is not to blame 08 Apr 2008

RSA 2010: Special Report

All the news from the security event of the year 03 Mar 2010

related white papers

today's top stories

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Genuinely intuitive technology is years away

If the aim of technology is to simplify our lives, then it has failed 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Clouds reflected in office blockFeatures

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

Dale VileFeatures

Defining cloud computing

Making sense of what cloud means to your business involves evaluating the options and clarifying the benefits you expect from its implementation, writes Dale Vile 08 Sep 2010

Primary Navigation