Access and Feeds

Security: Organizations Overconfident in their Security Preparedness

By Dick Weisinger

Are you confident in your organization’s information security strategy?  If you are, you’re in the company of quite a few.  72 percent of organizations were pretty confident that they are doing a good job with handling information security.  And as many as 43 percent of senior executives in organizations even thought that their organizations were actually best-in-class in their approach to security.  The problem is though, it turns out that only 13 percent of companies actually are in good shape security-wise.  Those are results published by PwC in their report 2012 Global State of Information Security Survey.
The report identifies four categories of organizations in their approach security.  The survey asked respondents to self-categorize their organizations.
  • Front-runners are those organizations that have their security act together.  They spent the time to create a well thought-out  security plan and they then proactively execute it.
  • Strategists have taken the time to create security plans but, for whatever reason, have failed to execute it
  • Tacticians haven’t bothered with creating a plan but still have managed to do a good job in achieving a high level of security
  • Firefighters have no security plan and are totally reactive to threats when they occur
One of the few areas where the report uncovered some good news is with security awareness.  Thanks to regulations like Sarbanes-Oxley and headline news stories in the media about security exploits, people are very aware that information security is an important issue.  That’s backed up by the results of the PwC study which  shows  that over the last five years that security awareness has significantly increased.  But the bad news is that those same organizations where awareness is high, not much has been done about it.  The report finds that security capabilities across most organizations have actually been degrading rather than improving.
The report finds that the three main areas where organizations need improvement are:
  • More support and backing from C-level executives
  • Better planning and execution for security related to Social Media data
  • Security for data being stored in the cloud
Organizations that truly are leaders in implementing security were identified to have the following characteristics:
  • Have both a Chief Information Security Office and a Chief Security Officer
  • Have created an overall information security strategy
  • Regularly review and measure the effectiveness of their implementation
  • Employed dedicated security personnel
It’s an interesting report from PwC, and the authors did a great job in making the results of the report accessible by creating an  interactive web page that allows the reader to drill down and visually investigate all the data collected in the survey.
Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*