Spotlight - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Enterprises Spend Too Much on Compliance

    in Spotlight



    Article Rating:starstarstarstarstar / 1
    Article Views: 2556

    Organizations are leaving their corporate secrets unprotected as a result of out-of-balance budgets that too strongly prioritize compliance over risk mitigation.

    Rate This Article:
    Add This Article To:

    Results out this week from a new survey of IT security decision-makers show that even though enterprises may be improving their compliance efforts, organizations are leaving their corporate secrets unprotected as a result of out-of-balance budgets that too strongly prioritize compliance over risk mitigation.

    Conducted by Forrester Consulting on behalf of Microsoft and RSA, The Security Division of EMC, the survey queried 305 IT leaders around the globe. It showed that 90 percent of these leaders believe that with PCI-DSS, data privacy laws, data breach regulations, and existing data security policies is the primary driver of their data security programs, spending on average about 39 percent of their budgets on compliance-related data security programs.

    However, when the survey examined the make-up of enterprise information portfolios, it showed that organizations are misplacing some of their priorities. Though the primary driver is pushing for protection of the "custodial data" covered by compliance--things like customers' and employees' personally identifiable information--this data only makes up 38 percent of the typical information portfolio. Corporate secrets--business critical IP--comprises about 62 percent.

    "This strongly suggests that investments are overweighed toward compliance," Forrester concluded in the survey.

    According to Sam Curry, marketing CTO for RSA, even though companies should still be spending money on protection of customer, medical and payment card information, they need to shift some focus to intellectual property and data that means something to actual business operations.

    "If IP is lost, it can cause long term competitive harm to an organization. The recent and highly-sophisticated attacks targeting intellectual property of large multinational companies are examples of this type of loss," Curry said.

    The survey found that not only is there an imbalance in which information is protected, but also in what types of loss are prepared for. Survey respondents showed that the bulk of organizations primarily focus on data security incidents relate to accidental loss. But at the same time, respondents showed that employee theft of sensitive information is 10 times costlier than accidental loss on a per-incident basis, often the difference between tens of thousands of dollars and hundreds of thousands of dollars.

    Perhaps one of the reasons that organizations are failing to properly prioritize is because they're still failing to measure the effectiveness of their security programs, Forrester concluded.

    Despite a wide range in security spending, views on the value of information and the number of security incidents reported among the respondents, nearly every company surveyed rated its security controls to be equally effective.

    "Most enterprises do not actually know whether their data security programs work or not, other than by raw incident counting," the study read. "'Compliance' in all its forms has helped CISOs buy more gear. But it has distracted IT security from its traditional focus: keeping company secrets secure."

     




    comments dic


     
     
    >>> More Spotlight Articles          >>> More By Ericka Chickowski
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement