Saturday | 5 July, 2008
Computerworld

Westpac admits to security blunder in outsourcing deal
Michael Crawford 04/08/2006 11:18:23

Related Features
  • +

    It Is the Business, Stupid 10/12/2006 13:59:51

    When projects go pear-shaped it's usually because there's too much focus on technology, and not enough on business outcomes and associated change
    In a 2005 article"Why Software Projects Fail", Cutter Consortium Fellow Robert Charette narrates an infamous anecdote about a disappearing warehouse.
  • +

    When Egos Dare 05/06/2007 10:17:02

    For some observers and practitioners, the federated model brings the best elements of centralization and decentralization to the IT table. Others aren’t so sure . . .
    The monarch was dead. Demoralized and shaken, the organization spent time mourning for a popular and high-profile CIO who had reigned for many years. Then, with time starting to dull the pain, the young princes began sharpening their knives, sensing their best opportunity in years to seize power
  • +

    Doing Your Sums on . . . Build, Buy or Rent 05/11/2007 13:32:30

    You’re trying to build a world-class IT team, but everyone’s going after the same talent pool. What mix works best? Should you grow your own, draft your players or barter your way to the line-up you want to field?
    CIOs should never forget that while new technologies have a maturity cycle, the maturity cycle for human beings in IT is even longer
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
  • +

    No Comparisons 03/04/2007 14:14:02

    Benchmarking your outsourcer’s prices against the market is the best lever you have to save money. Too bad your outsourcer may be trying to stop you
    When Darius Jackson became ING's head of IT infrastructure support and service delivery in January 2005, his job was to clean up a mess. two years earlier, the financial services company had outsourced its IT infrastructure (hardware, software, help desk and so on) to a major service provider in a seven-year, $US600 million deal. But now the business leaders of the company are worried that they aren't getting the value they want out of the relationship.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualization technologies, products, news and features.
RSS Feeds

Westpac Bank has admitted that IT security has been the one casualty of its 10-year, $4.3 billion IT outsourcing deal with IBM GSA which was inked in the year 2000.

Admitting that Westpac made a "small blunder" by outsourcing security as part of the massive outsourcing contract, Westpac's chief information security officer and CIO of enterprise services, David Backley, said the bank has struggled to get security, and especially staffing levels, back on track.

Backley likened the scenario to a struggle and said outsourcing employees was the most difficult element of the deal.

Under the contract, which covered infrastructure, desktop, e-business, mainframe, mid-range, and telecomms, around 1000 of the bank's IT staff were transferred to IBM.

Backley said the bank is only now getting the pendulum to stand still a little and getting better traction in shifting security labour without it costing the bank.

"In 2000, when we outsourced to IBM Global Services over 10 years, we made a small blunder in that we outsourced the security team and we were left with one person in-house who now works for the National Australia Bank (NAB); he was the guardian of information security at Westpac," Backley said.

"This didn't work so well as we struggled to get IBM to understand, so the battle continued for a while.

"The guys we initially had in our security team had been difficult to deal with; but when we outsourced they were moved to an organization they did not want to work for so they went from an internal group that was difficult to work with to an external contract, which was impossible."

As a result, he said Westpac created a small, embryonic security team to assess, with IBM GSA, what was required at the bank.

Blackley said over the past three years the bank and IBM GSA have been able to get the mix right.

He said the relationship has worked and now has a good understanding of what is required from the Westpac security team which is basically policy, some technology and policy policing, with IBM GSA providing services.

Today, Blackley said Westpac has created a matrix of security services, each with a specified amount of prescribed labour - a mechanism Backley says has taken the bank on a different journey by providing "much better traction".

Although rumours had been circulating for years and had reached Computerworld about the bank's in-house IT security problems since outsourcing to IBM, Westpac had remained tight-lipped, choosing not to respond to repeated enquiries from Computerworld in the time since the deal was signed.

It is the first time Westpac has provided a frank assessment of some of the challenges of outsourcing security which was delivered at the IT Security Summit in Sydney last week.

Backley also used his presentation to push the notion of customers adopting a single, trusted identity for banking services, saying it's a worthwhile concept that may take years to get final agreement.

"We will start to see sporadic, two-factor identification and sporadic, company-based smartcards moving towards a singular community of financial services; it takes time to get people into the space of co-opetition," Backley said.

"We have always lived with financial losses and fraud in banking as it is a risk you take, but what worries us is reputation damage, not just to Westpac as a bank or the NAB but damage to the entire financial services industry.

"If cybercrime and other forms of fraud erode trust where will we go? We do not want a loss of confidence in new banking channels."

IBM declined to comment for this story.

Market Place

Computerworld Member Login


 

Beyond Virtualisation - The Roadmap to 2012

CIO Breakfast Briefing
8:30am - 10:30am

Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt

Attend and discover:

  • What happens after virtualisation
  • The benefits automation drives
  • When automated infrastructures will emerge
  • What the roadmap to 2012 looks like
  • How to deliver an automated architecture
  • How to maximise your investment in virtualisation
Whitepaper

Top Tips for Email Security in 2008

E-mail security remains a difficult issue for IT managers, who are now faced with more malicious threats than ever before. So what’s new in e-mail security in 2008? And what will work best for your business? Read on to discover & create your 2008 e-mail security goals.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links