Infosecurity teams still isolated

New research from Ernst & Young finds many security teams are still struggling to integrate with the business

Written by Phil Muncaster

Information security teams are still isolated from the decision-making process in organisations and many are struggling to recruit the right level of experienced professionals, according to the latest Global Information Security Survey from consultancy Ernst & Young released today.

The annual survey, which is based on interviews with executives from around 1300 organistions, found that nearly a third of firms' infosecurity teams never meet with their board and meetings with IT are three times more likely than they are with business leaders.

However, there is some "light at the end of the tunnel" according to Ernst & Young's head of information security for northern Europe, Seamus Reilly. "Most firms are looking at enterprise risk and operational risk and bringing the, together and information security is part of that risk," he explained. " Four out of five do some integration of information security into risk management and 29 percent have fully integrated."

Reilly added that many IT security teams are in a dilemma in that although nearly half recognise that helping the business meet its objectives is one of their most important drivers, they can't do this because they are not integrated enough into the risk management function.

"If you're not in the appropriate place in an organisation, how can you make a contribution to the delivery of business objectives," he argued.

The report also found that many firms are struggling to attract enough skilled information security professionals, as the role of the function expands. Over half of respondents rated this as their number one challenge in delivering strategic information security projects.

To overcome this problem, Reilly advised firms to be more formal about identifying skills gaps and putting appropriate training programs in place, as they do for other areas of the business. He added that co-sourcing is also increasingly being seen as a partial solution to this problem.

"But if we're going to leap across the information security - business divide information security teams need to train their executive management [in the impact of security issues on the organisation]," he argued. "With all the recent incidents, when are we ever going to have a better occasion?"

But John Colley, European managing director of certifications organisation ISC2, argued that more investment is being made to train security staff. "Many organisations are dealing with the problem of finding experienced and trained resources, as highlighted in the survey, by employing less experienced staff and investing in training and education to get them up to speed,” he added.

Firms are also educating executives and staff on the impact of security issues, he explained.

“As a result we have seen a gradual shift in responsibility for securing information assets from the chief information officer (CIO) into other areas of senior management and business, including the chief executive officer, chief financial officer, chief risk officer and chief information security officer, as well as legal and compliance departments," said Colley.

Andrew Kellett of analyst firm Butler Group argued that the continuing isolation of IT security teams from the decision-making process was unsurprising, but added that the increased instances of data loss had pushed risk management and information security's place within this to the fore.

Kellett also argued that the lack of skilled security professionals may be due to its being not a clearly defined function in all but the largest organisations. "Everyone talks about the CSO with his team of people, but most are still fire-fighting," he added. "Unless you work in a very large organisation there is no career structure – [security] is probably not something you think of when you move into IT."

Tags:

reader comments

related articles

Safe door

Firms must face third-party security risks

Most organisations are in denial about the security risks of sharing data with partners, says Ernst & Young 16 Nov 2006

 

Firms failing on data sharing

Firms are acting to secure sensitive data, but third party risks remain 14 Nov 2006

Real time reporting threatens IT overhaul

Firms may have to release financial and performance information, as it happens 13 Nov 2006

Centralised police unit to lead e-crime fight

New organisation awaiting Home Office funding 10 Mar 2008

Infosec: Reputation driving information security

Security is now everyone's problem 23 Apr 2008

CSOs warned to invest in training

IT security teams risk being isolated if staff aren't given business skills, warns Ernst & Young 11 Jan 2008

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation