Westpac Bank has admitted that IT security has been the one casualty of its 10-year, $4.3 billion IT outsourcing deal with IBM GSA which was inked in the year 2000.
Admitting that Westpac made a "small blunder" by outsourcing security as part of the massive outsourcing contract, Westpac's chief information security officer and CIO of enterprise services, David Backley, said the bank has struggled to get security, and especially staffing levels, back on track.
Backley likened the scenario to a struggle and said outsourcing employees was the most difficult element of the deal.
Under the contract, which covered infrastructure, desktop, e-business, mainframe, mid-range, and telecomms, around 1000 of the bank's IT staff were transferred to IBM.
Backley said the bank is only now getting the pendulum to stand still a little and getting better traction in shifting security labour without it costing the bank.
"In 2000, when we outsourced to IBM Global Services over 10 years, we made a small blunder in that we outsourced the security team and we were left with one person in-house who now works for the National Australia Bank (NAB); he was the guardian of information security at Westpac," Backley said.
"This didn't work so well as we struggled to get IBM to understand, so the battle continued for a while.
"The guys we initially had in our security team had been difficult to deal with; but when we outsourced they were moved to an organization they did not want to work for so they went from an internal group that was difficult to work with to an external contract, which was impossible."
As a result, he said Westpac created a small, embryonic security team to assess, with IBM GSA, what was required at the bank.
Blackley said over the past three years the bank and IBM GSA have been able to get the mix right.
He said the relationship has worked and now has a good understanding of what is required from the Westpac security team which is basically policy, some technology and policy policing, with IBM GSA providing services.
Today, Blackley said Westpac has created a matrix of security services, each with a specified amount of prescribed labour - a mechanism Backley says has taken the bank on a different journey by providing "much better traction".
Although rumours had been circulating for years and had reached Computerworld about the bank's in-house IT security problems since outsourcing to IBM, Westpac had remained tight-lipped, choosing not to respond to repeated enquiries from Computerworld in the time since the deal was signed.
It is the first time Westpac has provided a frank assessment of some of the challenges of outsourcing security which was delivered at the IT Security Summit in Sydney last week.
Backley also used his presentation to push the notion of customers adopting a single, trusted identity for banking services, saying it's a worthwhile concept that may take years to get final agreement.
"We will start to see sporadic, two-factor identification and sporadic, company-based smartcards moving towards a singular community of financial services; it takes time to get people into the space of co-opetition," Backley said.
"We have always lived with financial losses and fraud in banking as it is a risk you take, but what worries us is reputation damage, not just to Westpac as a bank or the NAB but damage to the entire financial services industry.
"If cybercrime and other forms of fraud erode trust where will we go? We do not want a loss of confidence in new banking channels."
IBM declined to comment for this story.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
IT executives face the need to improve service delivery with limited resource increases. Two common strategies for achieving this are network and systems management tools and datacenter consolidation. Read on to disocover how you can make a strong business case for IT Consolidation.












