All the latest UK technology news, reviews and analysis

Lax e-security hinders dotcom funding

by Ian Lynch

30 Nov 2000

Be the first to comment

  • Tweet this

Inadequate security systems and management may lead to companies being blacklisted by City investors, according to a survey published this week.

The report, called A Risk Too Far and commissioned by internet service provider Vistorm, shows that while 26 per cent of managers demonstrate high levels of IT literacy, the majority don't understand how IT security can affect business performance.

As a result, some companies may be missing out on investment because they are being incorrectly identified as an above average risk.

Pension funds may also be missing out for the same reason. Fund managers wrongly regard dotcoms and financial services as being at greater risk from computer security breaches, the report said.

Ian McKenzie, managing director of managed internet services at Vistorm, said: "No particular business sector is more at risk than any other. But if e-security isn't given attention at director level, there will be enough high-profile security breaches to damage the development of ebusiness in this country."

Three key reasons were given for fund managers' views: a lack of verifiable information; a generally poor understanding of who is at risk and why; and a focus on assessment criteria that do not measure the impact of future market changes.

The report's recommendations include:

  • Adopting recognised frameworks such as BS7799 (soon to be ISO 17799) as a basis for a comprehensive security procedure.
  • Ensuring that IT security is tackled as a business, and not simply as an IT challenge.
  • Using external audits to validate the robustness of IT security solutions on a regular basis.

Chris Ferrant, e-product manager responsible for the BS7799 security standard at the British Standards Institute, said: "Security needs to be considered in relation to the value of its importance as an asset to the company. The technological solutions offered by the IT industry will only be successful if used within a managed environment."

The report follows on from research carried out by Network Associates - which ironically had two of its websites hacked this week - which called for chief executives to take responsibility for e-security.

Vistorm's research has now received the backing of both Certus, the association of IT directors, and the Computer Services and Software Association (CSSA).

John Higgins, director general at the CSSA, said: "The 26 per cent of fund managers who see IT security as a pervasive issue have got it right. Now, the IT industry must work together to get the other 74 per cent to see it the same way - otherwise the only Christmas cards we will receive this year will come with their own virus."

Blue chip companies that have suffered attacks which have made headlines this year include:

Microsoft, HSBC, Barclays, Powergen, Woolworth's, Credit Suisse, Safeway, Visa and Bloomberg.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

29%

1%

12%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Software Developer (.Net, VB.Net) – Skipton

Graduate Developer / Software Developer (.Net, VB.Net...

PHP Developer / Web Developer (PHP4/5, Object Orientated PHP)

PHP Developer / Web Developer (PHP4/5, Object Orientated...

Web Games Designer

Web Games Designer – Gibraltar Web Games Designer...

E-commerce Business / Systems Analyst - retail

An exciting opportunity for a Systems / Business Analyst...

To send to more than one email address, simply separate each address with a comma.