Security survey
Security survey

Security must include business continuity

Security threats have a significant effect on business - so are IT managers prepared?

Written by Computing staff

Business continuity used to be associated with disasters such as fire and floods.

However, according to the Global Information Security Survey, security threats now have a significant impact on business, and organisations need to make sure they have plans in place to protect themselves when hit by a security breach.

"Security is now seen as an important element of business continuity," says Richard Archdeacon, director of technical services at antivirus specialist Symantec.

"How do you continue to do business if you have a severe virus attack? What areas should be maintained? Which need multi-layered defences? Business continuity is being built into security measures."

About 90 per cent of European businesses suffered downtime over the past year, the research shows.

"That's very surprising to me," comments Jean-Paul Favier, unit manager of e-travel operation support at online travel company Amadeus.

"We've been running our website since 1996 and we've not had any downtime since then. However, it's important to differentiate between our site, which is our main channel to market, and other systems, such as email, which have been affected by things such as viruses."

Some three per cent of European firms suffered a loss of systems in the past year that lasted for six to 10 days, three per cent for three to six days, 14 per cent suffered for one to three days, 20 per cent eight to 24 hours, 21 per cent four to eight hours, and a further 29 per cent less for than four hours.

"Figures on downtime are useful in the sense that they impress upon company managers and owners that there are things that can happen to computer systems that result in them not working and then the business not working. That is an important message," maintains Peter Sommer, security expert at the London School of Economics.

Good management is vital when it comes to implementing security systems, and ensuring that processes are appropriate to the business and provide the best protection against attacks. Central to this is the security policy.

Some 73 per cent of North American respondents to the Global Information Security Survey said they include appropriate use of email in their security policies, but less than half take the same precautions in Europe, 49 per cent. It's even lower in Asia-Pacific countries, 48 per cent.

System administration was covered by 66 per cent of North American policies, 68 per cent of South Americans, 65 per cent of Europeans and 56 per cent in Asia-Pacific. Network administration featured in 62 per cent of North American policies, 66 per cent of South American policies, 62 per cent of European ones and 53 per cent of those in Asia-Pacific.

"Security policies are incredibly important and enforcing them is even more important," warns Peter Pedersen, chief technology officer, at interactive betting firm Blue Square.

"We all need a security policy," agrees Amadeus's Favier.

"At the start of any new application or site, it needs to be drawn up and adhered to. I think it's important to design your applications according to a strict policy. It's a requirement for us."

The survey found that the most common person in a business to set security policy is the chief information officer, a vice president or director of information services or IT, according to 48 per cent of North American businesses, 43 per cent of South Americans, 26 per cent of Europeans and 29 per cent of Asia-Pacific companies.

The president, chief executive or managing director was responsible for setting policy in 40 per cent of North American companies, 37 per cent of South American firms, 41 per cent of European businesses and 42 per cent of firms in Asia-Pacific.

Educating users is essential when implementing a security strategy, according to Graham Nugent, European strategic information services manager at UPS.

"At UPS, we believe that the best way of securing our information assets is by educating our users in all aspects of information security, and by continuing to reinforce the importance of security through our management group," he explains.

"We have had an Electronic Communications Policy document for some time now, and each of our users is required to sign a copy of that document to qualify for an access ID. We have a tradition in UPS of communicating with all our employees using a pre-work communication meeting.

"These events are highly structured, last three minutes maximum and are designed so that the manager talks and the workers listen. What a great way to get the latest information over to our people about email attachments, viruses and so on."

Jeremy Beale, head of ebusiness at the CBI, also sees education as an essential part of security management, but believes the government needs to be involved.

"There is a very large-scale education programme that needs to be undertaken, and we've been in discussion with the government and are getting nearer to getting that kind of awareness campaign launched," he comments.

"Many parts of government need to be involved, as do many sectors of the industry. It needs to be co-ordinated so that it is high-level, and addresses the different groups concerned."

Knowing how much security and subsequent disruption costs as a result of downtime is essential if businesses are to effectively manage security, according to the LSE's Sommer.

"Businesses need to be able to calculate the cost of business interruption. There are well-known disciplines within the insurance industry that people can draw on," he explains.

"One of the lessons you might draw is that security specialists need to understand the discipline for calculating consequential losses, because that might have an impact on the order of budget they are going to get from bosses to avoid it happening."

Some 22 per cent of European respondents to the survey said downtime that resulted from a security breach cost them up to $10,000. And 11 per cent cited between $10,000 and $100,000.

But 46 per cent didn't know how much attacks cost them.

Tags:

reader comments

related articles

IE buffer overflow vulnerability

IE bug allows hackers to take over PCs

Security group warns users to patch against buffer overflow vulnerability 05 Nov 2004

 

Bugwatch: Fast ways to protect your IT infrastructure

A practical, smart approach to IT continuity provisioning saves time and money 23 Sep 2004

IT security culture must start from the top

Global survey warns senior execs against 'delegating' security awareness 23 Sep 2004

You are still the weakest security link

Survey finds staff misuse of IT topping causes of business security breaches 05 Aug 2004

Symantec offers monitoring and intrusion prevention

Network Security 7100 series designed to stop infections from spreading 28 Jul 2004

Security threat growing in UK

But many users are ignoring best practice advice 07 Jul 2004

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack. 15 Apr 2004

Convicted forensics expert defends record

Stands by his work 11 Apr 2008

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation