Wake-up call to business: Tighten up on information security
According to the Department of Trade and Industry there are 4.5 million businesses in the UK of which 99.3% are small to medium sized enterprises (SMEs), employing 0-49 employees. These comprise 58.9% of the total workforce of 24.4 million and account for 51.9% of the £2,600 billion UK turnover. Bruce Hallas, a specialist in information security, said "SMEs are particularly prone to poor or even non-existent information security. As awareness of the importance of information security increases, the SMEs stand to lose competitiveness, potentially losing contracts with existing clients and suffering the financial consequences that are increasingly arising from information security incidents." An over reliance on Information Technology (IT) has developed over recent years. According to Hallas, this is the result of confusing Information Technology with Information Security (IS). With 'insufficient' money to invest in expensive information security expertise, many SME's are investing heavily in IT in the mistaken belief that IT will ensure IS. "Yet the largest business drivers for security investment are contractual, regulatory, market pressures from consumers, corporate clients and the public sector. Not the typical domain of IT. The biggest security vulnerability lies with people," Hallas says. "Security is about managing the risk from people, both known and unknown, interacting with your information and information systems. It is more about people management than technology."
Tyler Moore of the Computer Laboratories, University of Cambridge expanded, "Information security is now a mainstream political issue, and no longer the province of technologists alone," he said. "People used to think that the internet was not secure because there was not enough of the right technology, not enough sophisticated cryptographic mechanisms, authentication or filtering etc. so advanced encryption, public key infrastructure and firewalls were added. The internet did not get any safer," he added. "In 1999 it became clear that even the latest and greatest technology will not solve all our problems if those who protect and maintain them are not sufficiently movitated. The issue is one of incentives."
The impact of an under-incentivised workforce can have devastating consequences in business such as denial of service attacks allowing viruses to infect the IT system, hospitals putting access to data above patient privacy, bank customers suffering phishing attacks by poorly designed banking systems.
"Economics can explain many of the failures and challenges in a new way" Tyler Moore said. "As companies are beginning to realise the value of good information security practice so security measures are being used not only to manage the evils of the attackers but also to support the business models of companies."
Now that the Achilles heel of the information security problem has been identified, companies, especially banks, often fight shy of divulging information about attacks, whether they have been successfully repelled or not because the information concerned may be sensitive.
Help is at hand in the form of a new report "Security Economics and the Internal Market" which outlines police options regarding the economic problems in providing IS.
The report's first recommendation is for the EU to issue a comprehensive breach notification law to notify consumers when their details have been compromised so they can protect themselves.
Source: Economic & Social Research Council
Related
- New computer security guide can help safeguard your small businessTue, 6 Oct 2009, 20:17:41 EDT
- National survey finds information tech and business alignment a struggle for American companiesMon, 22 Sep 2008, 10:42:45 EDT
- Corporations rethinking IT's role in cutting corporate costs, boosting productivityMon, 5 Oct 2009, 15:16:07 EDT
- Argonne develops program for cyber security 'neighborhood watch'Thu, 16 Jul 2009, 16:15:28 EDT
- Carnegie Mellon researchers find social security numbers can be predicted with public informationMon, 6 Jul 2009, 17:30:28 EDT
Other sources
- Wake-up call to business: Tighten up on information securityfrom PhysorgMon, 30 Jun 2008, 12:14:23 EDT
Latest Science Newsletter
Get the latest and most popular science news articles of the week in your Inbox!Learn more about
Popular science news articles
- Facebook profiles capture true personality, according to new psychology research
- Shape shifters: Researchers create new breed of antennas
- Typhoon Nida's cloud tops dropping as it zigzags in wind shear
- Will copper keep us safe from the superbugs?
- Homicide rates linked to trust in governement, sense of belonging, study suggests
- First-ever blueprint of a minimal cell is more complex than expected
- Brain's fear center is equipped with a built-in suffocation sensor
- Implant-based cancer vaccine is first to eliminate tumors in mice
- New study finds men and women may respond differently to danger
- Tough yet stiff deer antler is materials scientist's dream
- Blushing dusty nebula
- Will copper keep us safe from the superbugs?
- Crime scene measurements can be taken from a single image
- Wistar-led research team discovers genetic pattern that indicates early-stage lung cancer
- New study released on World AIDS Day measures HIV anti-retroviral regimens' safety and efficacy
- Implant-based cancer vaccine is first to eliminate tumors in mice
- Study sheds light on brain's fear processing center
- Study shows new brain connections form rapidly during motor learning
- Brain scan study shows cocaine abusers can control cravings
- First-ever blueprint of a minimal cell is more complex than expected
- New evidence that dark chocolate helps ease emotional stress
- African desert rift confirmed as new ocean in the making
- Nanoparticles used in common household items caused genetic damage in mice
- New study links vitamin D deficiency to cardiovascular disease and death
- Polyphenols and polyunsaturated fatty acids boost the birth of new neurons