Cybercrime takes back seat to brand as CSO priority

Despite the escalating levels and sophistication of cyber crime, survey finds that harm to brand is the most unwelcome prospect for security bosses

Reputational damage is top of mind for information security leaders again. According to a global survey of more than 7,500 security professionals, 71 per cent said that avoiding harm to brand was their top priority, ahead of other hot topics, such as maintaining customer data privacy, controlling identity theft, and protection against breaches of laws and regulations. The study was conducted by researcher Frost & Sullivan on behalf of security professional certification group ISC2.

Howard Schmidt, a former White House security advisor, said the future of security lies in it being baked into systems, networks and processes. “Security is starting to be built into the infrastructure,” he said. “Before, it was like buying a car and having to buy the brakes separately. We’ve truly passed a tipping point.”

Schmidt added that consolidation in the sector was aiding that process with deals in the last couple of years, such as EMC buying RSA Security and Symantec combining with Veritas.

He also empathised with those who call for the restoration of a unit dedicated to tackling computer crime. “There’s this question of ‘should hi-tech be subsumed into some other organisation?’ Although I agree that consolidation is good within the industry, I think it’s a bit premature for public agencies. They should have a concentrated unit because otherwise they have to compete for resources.”

Louis Gamon, regional director of the Information Systems Security Association, was critical of the government and “how little it pays any attention to cyber crime. There’s a belief that it’s small beer, peanuts, but we’re losing more money in e-crime than to the drugs cartels.”

However, Schmidt cautioned that definitions of the nature of computer “crime” need care. “The perception is sometimes one of someone with sunglasses directing things from a Rolls-Royce when you use the term ‘organised crime’,” he said, noting that often groups of miscreants have no association with Mafia-type organisations or terrorism.

ISC2 board director Richard Nealon said security chiefs need increasingly to play a role in broader risk management, and applauded the role of regulations in mandating more secure regimes at organisations. “Today, risk management is part of the common body of knowledge if you’re setting up a company,” he said. “In the same way you put in accounting to manage finance, you put in security to manage risk. What the regulations have done is wonderful in terms of foreseeing the sub-prime crisis and the banks’ exposure. Sarbanes-Oxley made us document our processes and made them more robust and manageable. I thought it would be easy and very wooly, but it was painful. The silver lining is that it has turned out to be a great advantage to be SOX-compliant.”

Nealon said he is observing a rise in slicker, more professional, threats to security. “Until now, we’ve led a blessed life and our biggest threat was people who didn’t have a lot of malice, motivation, technology or education. They were script kiddies or enthusiasts, and most of the threats came from that vector. Now there is motivation and there is money to be made. They’ll produce a business plan, seek funding, allocate resources, and they basically do it for profit motives. They’re very sophisticated so, as an industry collectively, and as a business uniquely, we need to put controls in place to ensure we don’t become real targets.”

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Nealon also said that social networking threats remain a concern. “Security used to be mainly technology then process, so you would have a technology control such as anti-virus or intrusion-detection, and a process such as patching and updating. Now it’s the people aspect of the job that is hardest to control. Look at what Kevin Mitnick [notorious US cyber criminal] did. He was very charming and compromised systems through people.”

ISC2 board director and consultant Peter Berlich said that although the profile of security is much greater than previously, the roles of chief security officers were still dependent on the nature of employers and industries. “If you’re business is making soap, do you need to be on the board?” he quipped.

Related articles:

Criminals invest in crimeware-as-a-service



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

The challenge of strategic alignment

Recent research also shows that many organisations give too much prominence to internally generated KPIs – controlling the controllable – rather than looking outwards at threats and opportunities on the horizon which can ultimately be far more influential on performance.

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Managing email: Exploring common email management challenges (and how to overcome them)

We surveyed 157 IT professionals to understand the difficulties and opportunities faced by email managers. From this we were able to highlight some easy-to-manange solutions to their most pressing problems.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation - The 'black hole' of security?

Covering the set of issues, ideas and perceptions discussed during a recently held debate about the effect of virtualisation techniques on organisational security. This paper provides a comprehensive account of all the subject matters debated and concludes with key takeaways and IDC recommended actions.

DOWNLOAD

Trend Micro



* *