IT security bedevilled by poor 'me too' products

'Every ROI estimate is bogus'

Written by Iain Thomson

The IT security market has too many bad products because purchasers don’t know what they are buying, delegates at the RSA Security conference were told.

In his keynote address security expert and chief executive of BT Counterpane, Bruce Schneier, said that for every product that was good in the industry there would be a couple of 'me too' companies that were pushing poor products.

But because the area of IT security is so complex most buyers have no way of telling if a product is good and so end up feeling more secure than they really are, which in the long term is bad for the business.

"Bad products drive out good products," he said.

"That's very true in our market. If I have two boxed products, one of which is securely coded and one that isn’t, you have no way of telling the difference, there's no functional test you can do. So you buy the cheaper one."

He said that this had contributed to a situation where users were caught between feeling secure and actually being secure. There was not enough accurate information available for people to make informed choices.

He described what he called "security theatre" as security information that was designed to play on the emotions of security and not the realities of security.

"That's probably why every ROI estimate is bogus," said Schneier.

"Using high number mathematics I can make an ROI say anything and not change psychologically what you think of it."

Such security theatre is harming the industry because people need to feel secure as well as actually being secure, but at the same time it was sometimes needed because products needed to appeal to the emotions to sell.

An example of an application that was undersold was email security. Schneier said that products worked very well but were undersold.

In the long term he said that he was confident that industry would eventually get the balance right; pointing out that while there were few firewall companies left the features of the best ones were found in most.

Tags:

reader comments

related articles

BT buys security outsourcer Counterpane

Firm snapped up for undisclosed sum 25 Oct 2006

 

Schneier warns Microsoft over Vista security

Security guru concerned about security info overload  27 Apr 2006

Penny pinching firms make computer security worse

Money, not technology, can solve the sorry state of computer security 15 Feb 2006

Banks told to take responsibility for phishing

Security expert says that only financial institutions can end the problem 17 Oct 2005

Humans not evolved for IT security

Emotion and reality fight it out 23 Oct 2007

Tech industry launches initiative to boost software security

A major new industry initiative could ensure the quality and security of software 23 Oct 2007

RSA event to launch security push

Annual security conference will cover Web 2.0 risks and breach notification laws 22 Oct 2007

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation