Latest Comments
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM

Managing IT risk in unchartered waters of "Security 3.0"

  • Email a Friend
  • Print Page
Managing IT risk in unchartered waters of "Security 3.0"
By Rosalie Marshall
Sep 21, 2007 1:06 PM
Tags: Managing | IT | risk | in | unchartered | waters | of | "Security | 3.0"
Gartner’s IT Security Summit in London this week focused on the dangers to corporate systems posed by emerging “security 3.0-level” attacks that typically exploit vulnerabilities in social networking applications.

The analyst firm also warned that by the end of 2007, 75 per cent of enterprises will be infected with undetected malware that may cause hidden vulnerabilities in enterprise systems.

Gartner advised firms to use standard tools to deal with common “security 2.0” problems, such as worms and viruses, in order to free up security budgets and personnel to tackle the latest threats.

According to the firm, chief information officers have typically increased security spending by 9.3 per cent over 2006 as they attempt to bolster their IT defences.

However, Gartner research suggests that throwing money a security is not working. At the summit, the firm said that there is no correlation between security spending and the security level of a system. The firm added that progress in security should see a reduction in security spending, not increase it.

Once money is spent on securing a system against threats such as viruses, it is unlikely a huge amount will have to be spent again because these threats are not progressing, Gartner analyst John Pescatore said. This will free up money that can be focused on techniques to detect future, hard-to-perceive threats, he added.

Richard Hunter, another Gartner analyst, said the most important IT spending is on the foundation of systems, not administration. Many of the current problems are caused by poor technology and “management inattention”, he argued.

“Although fixing the foundation of a large infrastructure can demand large upfront costs, it will be cheaper in the long term and free up staff and money to deal with the new threats,” Hunter added.

Firms have a challenge ahead of them, according to Joanna Rutkowska, chief executive of security firm Invisible Things. She said organisations are in a constant race against the “bad guys” and that this means resources always have to be focused on the latest threats.

Pescatore agreed, saying “security 3.0” required IT staff to stay one step ahead of criminals and protect systems against targeted attacks by determined individuals.

Pescatore cited attacks on blogging software through back doors and the defacing of US senator John McCain’s MySpace page as examples of the kind of targeted incidents firms must defend against.

itweek.co.uk @ 2008 Incisive Media

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers