Awareness also requires action

Information security is everyone's business, but that message doesn't always filter up to the highest level of the organisation. New research from Ernst & Young finds that companies should be doing more to safeguard their data.

The 2004 Ernst & Young Global Information Security Survey is based on responses from 1,233 worldwide organisations. Of these respondents, more than 70% failed to identify training and raising employee awareness of information security issues as a top initiative.

Companies are generally focused on external threats such as viruses, and are putting technology measures such as firewalls and anti-virus software in place to reduce these risks. But not enough attention is being paid to internal threats.

"While the public's attention remains focused upon the external threats, companies face far greater damage from insiders' misconduct, omissions, oversights, or an organisational culture that violates existing standards," says Edwin Bennett, global director of Ernst & Young's Technology and Security Risk Services. "Because many insider incidents are based on concealment, organizations often are unaware they're being victimized."

Bennett recommends creating a security-conscious culture at the top. The CEO and the board must approach security as a way to gain competitive advantage and preserve shareholder value rather than as a necessary cost of doing business.

"More could and should be done to transform the skills and awareness of their people, who often present the greatest opportunity for vulnerabilities - and convert them into its strongest layer of defense," he says.

For the complete survey results, go to: http://www.ey.com/global/content.nsf/International/Home

More about: Ernst & Young, Ernst & Young

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/171/gadwin-web-snapshot/

Gadwin Web Snapshot

Gadwin Web Snapshot will effectively capture the entire page including all design elements when capturing web pages. It makes an image of the browser’s content ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia