CFO Expectations of IT


Follow us





Malice in Wonderland

Despite best efforts by enterprises and security vendors; recent news stories and the prevailing opinion of executives I talk with both indicate a growing concern over information theft from malicious activity. Is this concern justified?

Data from the threat assessments we have carried out across the globe would certainly seem to indicate that it is. Based on 130 assessments worldwide, 100 per cent of enterprises had active malware infections of which they were not aware and over 70 per cent of those were bots or information stealing malware.

It's well-known that the criminal underground is geared up for the theft of valuable corporate and personal information, with form-grabbers, men in the browser, bot &  VNC capabilities, automated exploit modules and mature partner delivery platforms. So why are the security industry and the enterprise not facing up to the challenge effectively?

Securing the enterprise environment is increasingly problematic as the environment itself is becomes ever more fragmented. Increased mobility, a more dynamic application landscape, cloud adoption and social networking all offer valuable opportunities to the enterprising criminal.

Alongside this, IT professionals are struggling to deal with the unending tide of patches required to fend off critical vulnerabilities, vulnerabilities that are actively exploited as soon as, or often before, the patch is made available.  Lewis Carroll was way ahead of his time; I can only think he was talking about patching when he wrote;

 "Well, in our country," said Alice, still panting a little, "you'd generally get to somewhere else -- if you run very fast for a long time, as we've been doing."

"A slow sort of country!" said the Queen. "Now, here, you see, it takes all the running you can do, to keep in the same place. If you want to get somewhere else, you must run at least twice as fast as that!"

Another factor that disadvantages the good guys is that we are mostly obliged to play with an open hand. Common operating environments are a known quantity to criminals, as is the common security and application portfolio. This means that they can focus their efforts on uncovering high value vulnerabilities that offer the most return on investment. Their own application environment though is much more closed and they can (and do) test their creations against all the known security vendors to make sure they are undetected.

It's not sufficient to base your layered security on the layers in your infrastructure or the layers of user behaviour. When considering security technologies, think about the layers on which modern threats operate; the exposure layer, the vulnerability layer, the infection layer and the execution layer.  Remember that malicious activity is not only inbound, deploy mechanisms that work on the assumption that the protected asset is already compromised, technologies that offer out-of-band monitoring and detection.

We need to combat the complacency that sometimes prevails in our industry, the way that things have always been done may no longer be the *right* way to do things. Just because your incumbent security system tells you everything is rosy, it doesn't mean you're clean, as many corporations are discovering to their cost.

Add to Technorati Favorites


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The cloud 2015 vision

Cloud computing is an important transition and a paradigm shift in IT services delivery - one that promises large gains in efficiency and flexibility at a time when demands on data centers are growing exponentially. The tools, building blocks, solutions, and best practices for cloud computing are evolving and challenges to deploying cloud solutions need to be considered.

The consumerisation of technology

iPads are the must-have fad. Android is the rising mobile platform -- Everywhere you turn, the news is about personal, smart, mobile devices and their impact on business and on IT.

Big data analytics

Broadly, there are two ways to think of Big Data technologies. The first is as an extension of what many organisations are already doing with business analytics. Gaining insight from business information is something that has been happening for decades, but the challenges and opportunities are now greater than ever before.

Virtualisation: benefits, challenges and solutions

The majority of organisations have already implemented server virtualisation and most intend to implement additional server virtualisation during the next year. The primary factors driving the movement to deploy server virtualisation are cost savings and the ability to dynamically provision and move VMs among physical servers. There are however, a number of significant challenges associated with server virtualisation.


CIO UK - Business - Technology - Leadership

On Demand Webcast
Analyse Data In Real Time


Increasingly businesses require the ability to analyse information quickly. Find out how to handle growing data volumes more efficiently while reducing the cost of managing your organisation's IT landscape

Watch now

SAP Logo

What do CFOs expect from IT?


Watch our sister publication's latest webcast.
Hear a case study from the Guardian News and Media's Technology Director, Andy Beale, and join the discussion on the role of the CFO in technology innovation.

Watch Discussion

CFO World webcast in assocation with Google

On Demand Webcast:
Maximising business flexibility with virtualisation


Register for this on demand webcast and find out how technologies can enable cost effective and secure virtualisation from your server deployments.



Watch now

Dell VMware logo


CFO Expectations of IT


* *