Corporate information security
Corporate information security

IT security culture must start from the top

Global survey warns senior execs against 'delegating' security awareness

Iain Thomson

Senior executives need to help companies build an IT security-conscious culture from the top down, according to new research by Ernst & Young.

Respondents to its Global Information Security Survey 2004 named lack of security awareness by users as the top obstacle to information security. But only 28 per cent of them listed raising employee information security awareness as a top initiative in 2004.

Advertisement

"I think the issue of security awareness has been delegated or abdicated to technical professionals some levels down in organisations," said Jan Babiak, managing partner of Ernst & Young's information security services in the UK.

"In general the sorts of people who have strong skills sets don't have the social networks and perspective to communicate policy to staff. I'm a big believer that you need the people at the top to take the lead and repeat the messages to staff."

Ernst & Young advised that companies should place more emphasis on creating a security-conscious culture that includes setting the right 'tone at the top'. But only one in five companies saw it as a chief executive-level priority.

Nearly two thirds of those surveyed did not have a chief information security officer, although more than half (53 per cent) of companies with revenues over over a $1bn a year did.

Viruses and Trojans are still rated the biggest threat overall, but employee misconduct was considered the second biggest threat. Theft of proprietary information was rated the lowest threat.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

UK losing the battle

UK firms 'sleep walking' into virus peril

IT managers blame lack of funds to defend against rising tide of attacks

Security survey

Security must include business continuity

Security threats have a significant effect on business - so are IT managers prepared?

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation