Top execs need to be involved in cybersecurity, study says
IDG News Service - Organizations with top executives who aren't involved in cybersecurity decisions face a serious problem -- a major hit to their bottom lines, according to a report released Wednesday.
"Many organizations see cybersecurity as solely an IT problem," said Karen Hughes, director of homeland security standards programs at the American National Standards Institute (ANSI), one of the major sponsors of the new report. "We are directing a wake-up call to executives nationwide. The message is, this is a very serious issue, and it's costing you a lot of money."
The report, called "The Financial Management of Cyber Risk," recommends how C-level executives can implement cybersecurity risk management programs at their companies. Part of the goal is to get executives such as chief financial officers directly involved in cybersecurity efforts, said Larry Clinton, president of the Internet Security Alliance (ISA), the other major sponsor of the report.
The report cites a cyberpolicy review released by President Barack Obama's administration last May saying that U.S. businesses lost $1 trillion worth of intellectual property to cyberattacks between 2008 and 2009. That number doesn't include losses due to theft of personal information and loss of customers, the report said.
The total cost of a typical breach of 10,000 personal records held by an organization would be about $2 million, the report said.
"We believe if we can educate American organizations about how much they're actually losing, we can move to the next step, which is solving the problem," Clinton said. Eighty to 90% of cybersecurity problems can be avoided by a combination of best practices, standards and security technology, but some organizations need to understand the financial problems associated with poor security practices before they will make changes, Clinton said.
A small percentage of company CFOs are directly involved in cybersecurity plans at their companies, and at many companies, most employees don't see cybersecurity as part of their jobs, Clinton said. "In American organizations, everybody has data," he said. "Generally, people don't think it's their responsibility to secure their own data. They think that's the job of the IT guys down at the end of the hall."
IT departments at many U.S. companies and organizations are viewed as cost centers, not profit centers, and are "starved for resources," Clinton added. Many employees don't understand, or are intimidated by, the cybersecurity tools their companies have, the report said.
U.S. organizations need to understand that in today's connected world, their lack of security can hurt their customers, their partners and national security, Clinton and other cybersecurity experts said at a press conference.
Cybersecurity product vendor Symantec released 2.7 million signatures to fight malicious code in 2009, more signatures than in the previous 25 years combined, said Justin Somaini, the company's chief information security officer. The majority of that malicious code was in the form of Trojans targeting intellectual property and personal information, he said.
Somaini called the ISA/ANSI report a "call to arms" for U.S. organizations.
"Most information security organizations struggle with implementing even the most basic solutions," Somaini said. "Most of the struggle comes from resistance within the organization."
The report recommends ways companies can deal with cyberrisk. Among the recommendations for top executives: Appoint a cyberrisk team, develop a cyberrisk management plan across all departments and develop a total cyberrisk budget.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- The Executive Buyer's Guide to Project Portfolio Management
- The Innotas Executive Buyer's Guide provides you with a concise overview of Project Portfolio Management (PPM) and delivers important buying criteria to help...
- Why Corporations Need to Automate IT Systems Management
- With corporate budgets being slashed and leaders expecting more out of their employees, companies are forced to do more with less, yet are...
- How to Launch a Successful IT Automation Initiative
- Corporations across all industries are under increasing pressure to cut costs and work more efficiently. In the race to meet both of these...
- Riverbed Services Platform Feature Brief
- Consolidation and virtualization are hot trends in IT, helping organizations increase their flexibility in delivering valuable services and reduce costs. The enhanced Riverbed®...
- Forrester: Top Mobile WAN Issues
- Are your workers going increasingly mobile? Don't wait for their calls to slam Support when they experience poor application performance on the road.... All Management and Careers White Papers
- Live Webcast
Integrated IT Operations Management in the Cloud - Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Integrated IT Operations Management in the Cloud
- Join award-winning technology editor Stan Gibson and Andrew White, CMO at Numara Software, to learn how asset management and service management are converging...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on Vmware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Management and Careers Webcasts