Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

'Advanced persistent threat' concerns boosting security budgets

Heightened awareness about stealthy network attacks designed to steal sensitive information -- what some call the "advanced persistent threat" -- is having an impact in raising security budgets and increasing executive management involvement in information technology, according to a survey published today.

The survey of 244 U.S.-based security professionals that was conducted by consultancy Enterprise Strategy Group (ESG) shows that the term "advanced persistent threat (APT)" is well understood by most, and 65% of the survey's respondents are concerned that APT attacks are undermining national security and the economy. The survey reveals that not only do security pros think APT is real, but 20% said "we are certain we have been targeted" and 39% said they were "fairly certain" their companies had been targeted.

Security roundup for Oct. 28: Cloud security holes; Facebook vulnerable?; China hackers lambasted

The headlines about APT -- whether it be the RSA break-in related to SecurID or any other known APT attack -- is sounding alarms in the executive suite as well.

This drumbeat of news is prompting the CEO, the chief financial officer, or others in executive management to take a range of actions impacting the IT department and the company. These include asking for risk metrics, beefing up employee training about APTs, hiring outside audits, and increasing security funding overall.

In fact, 32% of the security professionals in the survey said the APT problem "will cause us to increase security spending by 6% to 10%" and 11% said spending would even increase more than 10%. Only 16% said there would be no increase, and 7% either didn't know or said it was too early to tell.

Jon Oltsik, an analyst at ESG who led the research on the survey, says one goal he had with it was simply to find out whether IT security professionals considered the term APT to be a "serious threat" or more of a "marketing term."

"They do think it's a serious threat. And in most large organizations, they think they have been targeted," Oltsik said.

Also worried about APTs, the C-level executives are more energetically interacting with the IT and security department in ways not often seen previously. They're asking for board-level presentations on APT preparedness, and are increasing meetings with the chief information security officers (CISO) or IT risk team.

"The CEO is actually going to the CISO and saying, 'Tell me what this is, and what do you need from us?'" Oltsik said. "They're saying, 'We need real metrics and an action plan.'"

The survey points out that some C-level executives are going around the internal IT and security people to some extent by asking for an outside evaluation of internal security.

Oltsik says he's a little skeptical that training of end users to successfully resist APT attacks, such as targeted phishing attempts, will be worth it. But he adds if that's the case, IT departments should consider finding better ways to monitor network behavior, detect system compromises and perhaps make use of technologies such as whitelisting to lock down systems.

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: APT, etwork, Facebook, ISO, LAN, RSA
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Enterprise Strategy, Facebook, security
Latest Blog Posts
Whitepapers
  • The mobile print enterprise - How IT consumerisaton is driving anytime, anywhere printing
    The widespread adoption of smartphones and tablets, across Android, BlackBerry and Apple iOS platforms, has broadened the effectiveness of professional workers to remotely support business requirements. A continued reliance on printing amongst many businesses means IT must provide enterprise mobile printing capabilities that are secure and reliable. This not only ensures employees remain productive but also allows mobile printing to be tracked and controlled – vital in an era when many businesses face financial, environmental and security concerns. Read more.
    Learn more »
  • Removing BPM Silos to Unleash Process Power - 15 Best Practices for Enterprise BPM
    You are about to get a lot smarter about Enterprise Business Process Management (BPM ). T his article is the first in a series of our soon-to-be-published book, “The Intelligent Guide to Enterprise BPM .” So consider this first article your all-important primer.
    Learn more »
  • Avaya Deploys the Avaya Desktop Video Device with the Avaya Flare® Experience
    A revolutionary new video collaboration device, the Avaya Desktop Video Device has been making waves in the communications industry ever since Avaya introduced the product in the fall of 2010. Avaya’s own employees have been among the earliest users and have seen first-hand how the product can improve collaboration and make people more efficient and effective. Read more.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments