Experts see era of insecurity

Inadequate laws, insufficient defences, complacent ISPs, flawed software, and evolving spam and viruses mean trouble ahead

Written by Madeline Bennett & Dinah Greek

IT leaders, government officials, security vendors and analysts at the recent Infosecurity Europe event heard that firms are facing growing threats to their systems.

Delegates were told that the number of malicious attacks has been rising, and is expected to grow further over the next year.

The DTI published its Information Security Breaches Survey 2004, with figures that indicate many firms are still not giving security the attention and resources it deserves. Over half of firms spent just one percent or less of their IT budgets on security last year; and very few were taking steps to estimate the value of their security expenditure.

Security standards and certifications were widely ignored, despite being promoted by the government and security vendors. Almost two thirds of large UK organisations were unaware of the contents of the British security standard, BS7799. And three quarters of those responsible for IT security in large enterprises did not have any formal security qualifications.

Firms were advised not to assume that developers of software and systems would provide safe products free from vulnerabilities. "Security is an afterthought as it always has been and always will continue to be," warned Fred Cohen, principal analyst at research firm Burton Group. "Application and operating system security is the root problem. Developers are just not doing their jobs well and convenience is still winning out over security in many cases."

Stephen Timms, minister of state for e-commerce, added, "Information security problems are a routine part of everyday business life. All of us have to roll up our sleeves and deal with them."

Spam, though traditionally not viewed as an IT security issue, was high on the show's agenda. "Spam and viruses are converging, and are becoming one and the same attacks," said Cohen.

Delegates were told that spam is unlikely to be stopped by European and US anti-spam laws. Email security firm MessageLabs said that new laws had not reduced the amount of spam sent and could in fact be making matters worse.

MessageLabs' chief technology officer, Mark Sunner, said the US Can Spam law and the EU Privacy and Electronic Communications Directive had created confusion and gave companies a false sense of security. "These laws are probably creating more problems than they are solving," he argued. "We can show the legislation is not working because we have collated the data and are seeing the growth rates in spam since they were introduced."

Sunner argued that the Can Spam Act has a major shortcoming. "It assumes spammers are scrupulous and will abide by the law," he said. "The EU directive is confused and is being interpreted in different ways by each member state."

Jean-Jacques Sahel, deputy head of e-communications policy at the DTI, said harmonisation of global anti-spam legislation was needed, but he defended the EU privacy law. "There are slight differences in national laws [in EU member states] but overall the directive is quite solid in the way it is implemented across the EU," he said.

Sahel said that the DTI would put information on its web site by the end of May to show how countries were interpreting and implementing the directive.

Sunner added that ISPs could do more to protect end users. "If the water that came out of your taps was filthy and you had to filter it you wouldn't be very happy," Sunner said. "ISPs are basically giving us the equivalent of sewage. If they installed protection at the internet gateway this problem could virtually disappear."

Tags:

reader comments

related articles

Prolific US spammers

US blamed for 85 per cent of spam

Can-Spam law having little effect on US junk mailers 18 Aug 2004

 

Worried firms consider email boycott

Security concerns threaten future of 'everyone's favourite killer app' 16 Jul 2004

Patching gap gets narrower

The grace period between patch release and the first wave of attacks is disappearing fast, experts warn 02 May 2004

Vendors feel security heat

IT buyers are putting growing pressure on vendors to improve security 26 Apr 2004

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation