Home > Information Security News > Reports show security awareness and training are still lagging
Information Security News:
EMAIL THIS

Reports show security awareness and training are still lagging

By Ron Condon, UK Bureau Chief
16 Oct 2008 | SearchSecurity.co.uk

Security UK News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

While security budgets are remaining steady, despite the economic downturn, recent research from Ernst & Young Ltd. and PricewaterhouseCoopers LLP shows a lack of targeted spending and an over-reliance on technology to achieve security. Poorly trained people remain the weakest link.

The 11th Ernst & Young Global Information Security survey, which surveyed 1,400 organisations in 50 countries, found that only 44 per cent of respondents were training their staff in data handling, even though they were still continuing to fund investment in security tools.

Seamus Reilly, director in technology and security risk services at Ernst & Young, said the UK was broadly in line with global trends, but there were exceptions.

For instance, Reilly, providing additional specifics from the study, said the UK lags behind in strategic planning for security. While 18 percent of global organisations admitted they had no documented strategic plan for security over the next three years, the figure in the UK was 30 percent.

"UK companies need to be sure they are spending their budgets in the right places, and for that you need to have an information security strategy," said Reilly.

On the other hand, UK security professionals have more contact with senior company stakeholders, with 54 percent of them meeting with the audit committee on a quarterly or half-yearly basis, compared to 32 percent globally. Privacy is also a higher priority in the UK, with 88 percent of respondents implementing privacy controls and 83 percent saying that they now have a clear understanding of privacy law, 17 percent higher than
the global average.

Management of third-party risk is also a higher priority in the UK with 58 per cent of companies including information security requirements in contracts with external suppliers, compared to a global average of 45 per cent.

But although many defences are in place, Reilly said many basics of security were still overlooked. "You need to understand what personal information you have in the organisation, and have an inventory of [the data] -- many organisations have not even done that yet. It is the basis of dealing with personal information appropriately," he said.

"Many incidents in the UK come down to people acting inappropriately -- either not following a policy, or just trying to help someone else, and releasing information. There is a disconnect -- we have not yet tackled the personal awareness problem yet in the UK."

That conclusion is echoed by the latest PricewaterhouseCoopers annual Global State of Information Security Survey. After surveying 7,000 information technology executives from 119 countries (over 300 from the UK), researchers found that most UK companies in the sample did not know where their data was located, 37% weren't sure how many incidents they had had and more than half could not say what types of security incidents had occurred or what had caused them. About a third of companies had neither measured nor reviewed the effectiveness of their information security policies over the past year.

The study also concluded that although UK companies have invested heavily in technology for information security, they tend to focus on purely technical safeguards.

To view the reports, visit www.pwc.com/giss2008 and http://www.ey.com .



Tags: Security Policies and User AwarenessInformation Security Risk Assessment: Methodology and AnalysisData Breach Incident Management and RecoveryVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
How to write an information security policy

Information Security Risk Assessment: Methodology and Analysis
Improving software with the Building Security in Maturity Model (BSIMM)
Encryption basics: How asymmetric and symmetric encryption works
Getting the most out of the gap analysis process
Jericho Forum to provide customers with good security questions to ask
A guide to internal and external network security auditing
Insider threat detection still a challenge for employers
Get more out of your security event log data
Secure cloud computing: a contradiction in terms?
Report: U.K. lags in information security management practices
Aligning network security with business priorities

Data Breach Incident Management and Recovery
Make PCI DSS compliance easier by reducing scope, outsourcing data
Full disk encryption: Safer and easier than file and folder encryption
PCI DSS requirements: Get ready for stricter enforcement, fines
Data breach costs continue to rise in 2009, Ponemon study finds
Data Protection Act breach could cost companies 500,000 pounds
Jericho Forum to provide customers with good security questions to ask
Verizon report goes deep inside data breach investigations
Insider threat detection still a challenge for employers
Layoffs prompt insider threat fears, cybersecurity survey finds
ArcSight boosts system log management capabilities

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Financial Services Authority  (SearchSecurityUK.com)
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts