In the battle to balance budgets, security is losing

By Angela Gunn | Published May 20, 2009, 6:15 PM

Information security doesn't have the easiest time in the budget process even under the best of circumstances, but many observers had hoped that the threat of greater risk in tough times would shield security budgets from cost-cutting moves that could prove dangerous in the long run. Sadly, that's not what Deloitte's recent Global Security Survey for the Technology, Media & Telecommunications Industry is seeing out there.

There's not a lot of optimism afoot when you feel compelled to call the Key Findings synopsis of your report "Losing Ground," but the information Deloitte's researchers turned up is actually more nuanced than that -- it's not just that the budgets are getting smaller, but that the threats are getting bigger. (Last year's report, for the record, was titled "Treading Water"; before that we had "Protecting the Digital Assets.")

During the 12-month period covered by the survey, less than a third of Deloitte's global respondents (32%) had actually reduced their info-security budget, but a full 60% said they were either falling behind the threats or still trying to catch up on threats already out there. Just 29% say that their security spending is on track.

Among those extant threats, says the survey, are some associated with social networking. Unlike some companies, the report doesn't have a knee-jerk reaction to the phenomenon -- used correctly, says the authors, blogging and social networks can "help a company challenge and sharpen its thinking." But Web 2.0-related vulnerabilities and the increased potential they provide for social engineering are on the minds of 83% and 80% of the survey's 200-plus respondents, most of whom work at intellectual property-oriented firms with over 500 employees.

Based on the survey data, though, one suspects that security folk need to worry even more about the social network running from cubicle to cubicle. 41% of respondents said they'd discovered at least one internal breach over the last year, compared to 50% saying they'd been hit by an externally based attack. In turn, managers said that the biggest problem they faced internally was "excessive access rights." (Most noted, though, that the most common internal breaches were accidents -- an unencrypted thumbdrive goes missing, for instance, and it's an incident.) Only 28% believe they're adequately prepared to take on an actual attack launched from inside the company.

Rising fast on the breach front? Outsourcing and its discontents, with 56% of respondents saying they'd had breach trouble more than once in the past year with a "trusted" vendor. Not rising so fast? Scrutiny of those vendors' security situations. Just 20% actually review and test their partners' security arrangements, with even fewer adequately controlling vendor access to corporate data and systems. The report regards the situation as dangerous, especially were it to result in the leakage of personally identifiable information (PII). noting that "in a tough economy... desperate companies may use legal channels as a way to make up for reduced operating income."

Security folk have been fighting fires all around the organization for years, with mixed results. More companies than ever have their very own CISO -- 83%, compared to 65% just two years ago. Of those CISOs, 13 out of 20 reports directly to the C-level folks (especially the CIO) or to the board of directors. That's a surprisingly casual situation, though, since about 30% of those managers only take infosec status reports on an "ad hoc" basis. (Let us hope that not all of those meetings are prefaced by the phrase "Um, I'm afraid we have a problem.")

Face time matters -- especially around budget time, especially when times are strange. The precipitous decline in security budgets over the past year isn't only due to set-it-and-forget-it thinking higher up the food chain, but when just 6% of respondents say their IT budget has more than 7% set aside for security, you have to wonder about the effects of staying out of sight, especially since last year 36% of respondents said their security efforts received more than 7% of the IT budget. The Deloitte authors call it "a remarkable decline."

Also on the decline: Executives responsible for privacy issues. That's amazing in its own way, considering that regulatory issues are hotter than ever -- and, again, companies that aren't making money might be more quickly inclined to sue their way to some ready cash if necessary. The number of executive-level privacy officers is down 6% this year, and of those left just 20% report to either a board of directors or a C-level executive. nearly one company in five has no privacy policy at all.

Other survey numbers indicate that it might be thought around the company that security just isn't pulling its weight. (Perhaps a face-time issue; perhaps not.) 90% of companies surveyed do attempt to measure whether security projects are delivering as promised. Of that group, just 22% believe that projects deliver as promised, and 78% of respondents say that infosec efforts are at most "somewhat" effective.

The Deloitte survey is available from the company's Web site.

Comments

View comments by with a score of at least

as far as security for i.t., the business's are making lots of profits and paying big money to their executives and share holders.

if they don't want to allocate some of that money for their security, then it is their problem.

we can be assured that though we might think business's are tightening their budgets during these tough economic times, the exec's are being financially rewarded.

as far as the exec's are concerned, being poor and unemployed is not their problem.

Score: 0

|

Honestly, they don't seem to find poor and unemployed and identity-pwned their problem either -- at least not right away. (It's ironic that someone who enjoys quarterly earnings reports as much as I do thinks that the quarterly-results systems is just so damned bad for companies.)

I'm thinking right now of the TJX hack. When we all realized just how extensive it was and how sloppy the security had been, I was sure TJX was going down in flames. Just dead certain. Long story short, no -- no significant effect on sales, very limited consumer concern about the problem, just nothing. Years later, we *are* on the cusp of some pretty big financial penalties for the company, or so one is given to understand, but somehow I doubt it's going to have the same impact on those TJX execs nearly three years down the line.

And they wonder why security folk get cynical!

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.