Today's most compelling technologies are giving you the biggest security headaches. Social networking sites such as Twitter, Facebook and LinkedIn enhance collaboration and help your company connect with customers, but they also make easier than ever for your employees to share customer data and company secrets with outsiders.
Virtualisation and cloud computing let you simplify your physical IT infrastructure and cut overhead costs, but you've only just begun to see the security risks involved. Putting more of your infrastructure in the cloud has left you vulnerable to hackers who have redoubled efforts to launch denial of service attacks against the likes of Google, Yahoo and other Internet-based service providers. A massive Google outage earlier this year illustrates the kind of disruptions cloud dependent businesses can suffer.
But there's also good news. Even though the worst economic recession in decades has compelled you to spend less on outsourced security services and do more in-house, your security budget is holding steady. And more of you are employing a chief security officer.
Such are the big takeaways from the seventh annual Global Information Security survey, which CSO and CIO magazines conducted with PricewaterhouseCoopers earlier this year. Some 7,200 business and technology executives worldwide responded from a variety of industries, including government, health care, financial services and retail.
These trends are shaping your information security agenda.
"I have seen examples where companies are making bigger investments in training over time to make internal staff more security savvy," says Miguel Lopez, an IT security practitioner who has worked for such companies as MSC Software and Stamps.com. Part of the reason is that regulatory compliance pressures have jolted open the eyes of top brass who may have been blind to their internal security needs previously. Lopez points to one of his friends in the industry for an example of how things have changed. "My friend, an information security manager, sits on an executive security committee with doctors and other non-IT personnel," he says. "Security is being heard from and listened to more now than ever before."
Read on to learn what we found.
Social Networking opens new attack vectors
In less than two years, social networking has gone from an abstract curiosity to a way of life for many people. When someone updates their status on Twitter, Facebook or LinkedIn, they might do it at work by day or on company-owned laptops from home at night.
What gives IT executives heartburn is the ease with which users could share customer data or sensitive company activities while they're telling you what they're having for lunch. Cyberoutlaws know this and use social networks to launch phishing scams.
In one popular attack, they send their victims messages that appear to be coming from a Facebook friend. The "friend" may send along a URL they insist you check out. It may be pitched as a news story about Michael Jackson's death or a list of stock tips. In reality, the link takes the victim to a shady website that automatically drops malware onto the computer. The malware goes off in search of any valuable data stored on the computer or wider company network, be it customer credit card numbers or the secret recipe for a new cancer fighting drug.
It's no surprise, then, that every IT leader surveyed admitted they fear social engineering-based attacks. Forty five percent specifically fear the phishing schemes against web 2.0 applications.
Nevertheless, for many company executives, blocking social networking is out of the question because of its potential business benefits. Companies now clamour to get their messages out through these sites, so the challenge for CSOs is to find the right balance between security and usability.
"People are still incredibly naive about how much they should share with others, and we have to do a better job educating them about what is and isn't appropriate to share," says H. Frank Cervone, vice chancellor of information services with Purdue University. "We have to do a better job of enhancing our understanding of what internal organisation information should not be shared."
But in a university setting, it's critical to engage people through social media, Cervone adds. Even in the commercial sector, he doesn't see how organisations can avoid it.
And yet this year, the first in which we asked respondents about social media, only 23 percent said their security efforts now include provisions to defend web 2.0 technologies and control what can be posted on social networking sites.
One positive sign: Every year, more companies dedicate staff to monitoring how employees use online assets, 57 percent this year compared to 50 percent last year and 40 percent in 2006. Thirty-six percent of respondents monitor what employees are posting to external blogs and social networking sites.
To prevent sensitive information from escaping, 65 percent of companies use web content filters to keep data behind the firewall, and 62 percent make sure they are using the most secure version of whichever browser they choose. Forty percent said that when they evaluate security products, support and compatibility for web 2.0 is essential.
Unfortunately, social networking insecurity isn't something one can fix with just technology, says Mark Lobel, a partner in the security practice at PricewaterhouseCoopers.
"The problems are cultural, not technological. How do you educate people to use these sites intelligently?" he asks. "Historically, security people have come up from the tech path, not the sociologist path. So we have a long way to go in finding the right security balance."
Guy Pace, security administrator with the Washington State Board for Community and Technical Colleges, says his organisation takes many of the precautions described above. But he agrees with Lobel that the true battleground is one of office culture, not technology. "The most effective mitigation here is user education and creative, effective security awareness programs," he says.