All the latest UK technology news, reviews and analysis

Five steps to cutting IT security costs

by Phil Muncaster

20 Jan 2009

Be the first to comment

  • Tweet this
Security
Threats to enterprise systems are likely to increase in the downturn

Security chiefs were today urged to undertake a "cost-focused restructuring" of their departments to improve efficiency, survive job and funding cuts, and emerge better equipped to tackle the likely increase in threats during the downturn.

Stuart Okin, former Microsoft chief security advisor and now UK managing director of security consultancy Comsec, highlighted five areas that security leaders should focus on when approaching the board with cost-cutting initiatives.

"At the end of the exercise you should be able to save money, but at the very least you'll be reducing risk by focusing on these parameters," he said.

"We don't know how long the recession will last, but everyone's experience is that we're heading for a threat increase, and every department is under financial pressure."

Embedding security into the development lifecycle will remove threats from IT projects earlier, thus saving on the cost of recoding, while consolidating security service suppliers can reduce outlay through economies of scale, according to Okin.

Chief security officers should also look at removing unnecessary security technology in the enterprise.

"The world has moved on from strict firewalls and intrusion detection systems everywhere, because firms have opened up to third parties," Okin explained.

"So if you look at the controls, a lot of them are redundant, but people are fearful of removing them."

Okin urged companies to simplify the security environment, for example by combining Sarbanes-Oxley, International Organization for Standardization and Payment Card Industry security awareness training.

He also advised organisations to use many of the inbuilt security features of current products in order to boost cost containment and security efforts.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.