Are you clueless when it comes to the cost of adequate information security?
Don't worry - you're not alone.
I recently met with the CIO of a politely profitable biotech firm. His PR director sat across from him. It was like trying to talk about your bucks party with your mother at the table. He was chary to say the least. But there was one telling moment when this CIO let his guard down. The conversation had turned to security spending. Suddenly, the CIO's whole demeanour was made over. His shoulders went slack. He leaned in, interrupted a question and asked his own questions, rapid fire:"Do you know how much security spending is a good amount? Are there benchmarks? Do you have any numbers on what we should be doing?"
The CIO sounded eager - like a thief about to stumble upon the combination to a vault he'd been casing for months, and trying to hurry it along before his unwitting accomplice figured out what was going on. This was more than casual IT curiosity. This was Critical But Missing Business Knowledge.
Unfortunately, the answers to his three big questions were:"No idea","Not sure", and"Not really." Further investigation only deepened this mystery of how much is enough to spend on security.
It turns out, most of the security spending talk resides on the extremes. On the one hand, there's Joe Magee, former chief security officer at an online trading firm. With a face as straight as a pinstripe, he says:"I honestly believe 4 to 10 per cent of revenues should be spent on security." That's four to 10 per cent of total revenues, not the IT budget. Magee says he's got comfortable with the laughing in his face.
On the other hand, IT security consultant Brian Kelly said in an e-mail that some CIOs"don't even see information security as a NORMAL (EVEN PRUDENT) BUSINESS EXPENSE" (his capital letters). But the fact we don't know how much a company should be investing in its information security isn't, by itself, all that interesting. Many nice-to-have nuggets of IT knowledge like this elude us. Besides, the answer is probably "It depends."
Rather, the compelling mystery here is that we don't even know what CIOs are spending on security in the first place, never mind if it's too much or not enough.
If you think CIOs are guarded when they talk about security, imagine how they clam up when you're talking about security and budgets at the same time. Indeed, I got the sense from the biotech CIO that he's plain scared to say how much he's spending on security because there's a good chance his answer will meet one of two reactions: 1) His numbers are laughably excessive and he's wasting money, or 2) His numbers are so woefully inadequate that his enterprise is a fat bull's-eye for marksmen hackers.
Frankly, the truth could be either; he has no idea. This explains why the biotech CIO let his guard down. Basically, his barrage of questions amounted to: "Am I normal?"
No one knows. And good luck finding out.
- +
Ticked Off at Tick the Box Mentality 04 February, 2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
How to Get Real About Strategic Planning 04 February, 2008 12:50:59
Everyone agrees that having a strategic plan for IT is a good thing but most CIOs approach the process with fear and loathing. In fact, the majority of CIOs (and the enterprises they work for) are faking it when it comes to strategic planning. Isn't it time we all got real?Oh, it must be nice to be the CIO of a FedEx or a GE or a Credit Suisse. Places where IT and the business are so tightly aligned you can barely tell the two apart. Where corporate leaders understand that IT is a strategic asset and support it as such
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Delivering the Power of Choice with Microsoft Dynamics CRM
Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
How to improve employee productivity in small and medium businesses
Making the Business Case for IT Consolidation
Wireless LANs: Is my enterprise at risk?
Email Archiving 101—Customer Case Study
The state of Middleware
Strategies for Eliminating .PST Files
- White PaperLearn to tie virtualized computing to virtualized storage, to offer a dynamic set of capabilities within the data centre and create improved performance and system reliability. Discover how best to utilize EMC Celerra in a VMware ESX environment.
- White PaperJoin industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.
- White PaperWhat you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
CBS website bitten by iFrame hack 02 December, 2008 07:30:00
Russian malware distributors have launched another iFrame attack on a sub-domain of the cbs.com site.TV network CBS has become the latest big name to have it website used to host malware, a security company has reported. - +
Excerpt: Counterterrorism Strategies for Corporations 27 November, 2008 12:36:00
Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond.Mike Ackerman calls terrorism "the skunk at the globalization lawn party." His new book lays out 10 principles for how businesses can prepare and respond. - +
The 10 Ackerman Principles of Counterterrorism 27 November, 2008 12:43:00
Consultant and author Mike Ackerman's 10 counterterrorism principles for business.Consultant and author Mike Ackerman's 10 counterterrorism principles for business. - +
Survey: Despite Risks, Employees Still Holiday Shop at Work 27 November, 2008 10:02:00
As Cyber Monday approaches, research suggests a majority of workers will use their work computer to shop this holiday season. But despite the continued growth in online shopping, employees and business still don't understand the riskAs Cyber Monday approaches, research suggests a majority of workers will use their work computer to shop this holiday season. But despite the continued growth in online shopping, employees and business still don't understand the risk. - +
Why Cybercrime is Thriving 27 November, 2008 11:52:00
A new Symantec report reveals just how large and sophisticated the online underground economy has grownA new Symantec report reveals just how large and sophisticated the online underground economy has grown.
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 02 December, 2008 11:23:00
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 02 December, 2008 10:09:00
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 02 December, 2008 09:56:00
Virtual magic: HR specialist throws out 40 servers, adds 8TB SAN and saves $100,000 for disaster recovery 01 December, 2008 15:28:00
EXCOM scores back-to-back award trifecta 01 December, 2008 10:46:00
|
||
|
||
|
|
||
|
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Web 2.0 applications are all the rage, offering us tremendous value when it comes to collaboration and communication. They also open us up to new kinds of attacks however, and can cause problems in keeping systems and data secure. Read on to learn about the new attack methods and how you can defend yourself and your business.
















