CSO - Our coverage of the annual Global Information Security Survey conducted by CSO and CIO magazines in partnership with PwC has sparked some interesting discussions about what it takes to be a security leader. Specifically, the discussion is about how organizations can move from being a security laggard to something better. As part of those discussions, we spoke with Andy Ellis, chief security officer at Akamai Technologies. Ellis is responsible for overseeing the security architecture and compliance of the company's globally distributed network and sets the strategic direction of its security.
CSO: What attributes must an enterprise leader in risk management have?Ellis: This is a hard thing to measure. I think the important thing is that the organization actually understands the risks that apply to them, and that they are making intelligent decisions based on that risk profile. These are the organizations that are actually out front, leading the way, defining new risk models for themselves and selecting technologies and solutions that are appropriate for their business. It's about paving the way, not following somebody else's cookie cutter.
Companies seem to be spending a lot on security products, but not as much on strategic efforts. Do you think it's indicative of their already having effective strategies in place? Or, are they focusing just on the technology?In a down economy, you probably aren't spending time revamping your strategy. Hopefully, you're executing. That would be my guess as to what a lot of these organizations are doing. I think what you could be seeing is organizations saying "Look, I'm not going to try and rebuild my business continuity plan this year. It's not like we actually added a thousand people. I can run with the existing plan. It's much more important. Let's go execute on the strategy that we didn't finish from last year." I think industry often spends more time thinking about strategy and less time executing. That's what we're seeing in the survey results: "Hey, let's protect our jobs by going and executing on what people can see." Many times enterprises can see a strategic change in security, and if management can't see it, it may not have much perceived value.
A lot of companies seem to be skimping on disaster recovery and business continuity planning. Do you think there's a reason for this beyond it not being a priority, or organizations believing bad things won't happen to them?You have to look at it individually. For many businesses, that's a risk they have to take. I recall, after 9/11, there was an investment company that was praised for their business continuity plan. It was one of the investment companies that had been in the World Trade Center, and everybody was holding them up as this example of great business continuity planning. They had a good plan in place and they kept their business running after the attack. Three years later, the company was out of business. The reason was -- at the end of the day -- they didn't actually have a business continuity plan that dealt with how to keep the business successful after losing so many skilled knowledge workers. The point is that there are some events that are not worth planning for. And some companies, because of where they are at in their development cycle or whatever, can't afford to put a disaster recovery plan in place.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The High-Performance WAN Find out what are some of the top problems associated with large WANs and the technologies typically used to solve them.
- Building Your Network Management Toolset Network Management is one of things that is sometimes overlooked make sure you don't. Find out how to take advantage of it and...
- Optimizing the Network The network has become a utility that users can't do without. Mobility and bandwidth-hungry apps demand faster and more efficient networks.
- Ultra-Low-Latency Networking In a world where so much trading is systematic, millisecond delays matter. Low-latency, high-performance networking, therefore, has become a competitive imperative.
- Application Acceleration: Optimize the End-User Experience Watch this on-demand webcast and learn how you can optimize your web content, accelerate performance across any device and browser combination, and offload...
- Making Your Application Delivery Environment Cloud-Ready Join Kavitha Mariappan, Director of Product Marketing at Riverbed Technology, and Bob Laliberte, Senior Analyst at Enterprise Strategy Group, as they discuss the... All LAN/WAN White Papers | Webcasts