deloitte
Deloitte believes that the PCI Data Security Standard has done a lot to raise awareness
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Summit interview: Deloitte discusses security implications of the data deluge

We chat to Mike Maddison, UK head of Security, Privacy & Resilience Services, and Steve Cummings, special adviser to Deloitte's Security, Privacy & Resilience Group

Phil Muncaster, V3.co.uk 12 Nov 2009
ADVERTISEMENT

summit logo

V3.co.uk: How do you think the problem of information overload has contributed to poor information security?
Mike Maddison:
It’s been a fairly recurring theme of the past few years. A few years ago it was all about availability, with worms taking down networks. More recently, it’s shifted to confidentiality of information and organisations realising that information has an intrinsic value and is being targeted by groups. We’ve worked with every sector looking at information protection, and we’ve found in all sectors a huge amount of information has been retained, and duplicated within organisations, often for good reasons, and some of that information could be considered sensitive. So there has been a growth in retention of information often without any information governance strategy.

But are organisations getting there now?
MM: Yes – now there’s a recognition, and not just a technical one by IT, but a board level agenda. It’s driving interesting behaviours in organisations, because it’s happening higher up the food chain than previously. I’m optimistic because there’s a recognition that information security needs to be embedded in the day-to-day running of the business. The role of information protection is more visible too, as is the role of risk management. You just have to look at the number of CISO [chief information security officer] roles at a senior reporting level that there are now.

What is driving a greater awareness of information protection?
MM: The PCI Data Security Standard has done a lot to raise awareness among organisations that haven’t necessarily invested in securi ty before. It has added to the whole tone and tenor of what people need to do about data protection. There are large-scale privacy initiatives in a number of organisations now, whether it has been driven by the Financial Services Authority (FSA), the Data Protection Act or PCI. But there is still a challenge they face in understanding what information they hold – this is not just sensitive personal information either but corporate information – and where it flows out to the extended enterprise. It’s a big problem.

Why have security incidents still been happening, even with all the publicity they’re getting?
S
teve Cummings: I think with organisations it’s possible that the people who work with the data don’t recognise the value and importance if they deal with the stuff every day. They take it for granted and that needs to be recognised internally – organisations must put programmes in place to ensure the people who work there do recognise this. We’re seeing a kind of stick and carrot approach being adopted by many, so they will reward good behaviour with data and also enforce a system of compliance to make it clear that if something is done in the wrong way there will be consequences.

So education is the most important aspect?
MM: Yes, the right processes and technologies should underpin it but there needs to be an education piece embedded in the day-to-day operations. Unfortunately, the credit crunch has probably had an impact on that. Where organisations fail is when they do a one-off shot, especially on the awareness piece. If it’s not embedded and doesn’t happen on a regular basis they’re setting themselves up to fail.

SC: Most responses to government data breaches have been about cultural change, because the technology is already in place there. It’s about getting everyone at the right levels to understand this and act responsibly.

Tags: Web, Threats, Public-sector, V3-summit, Government, Security, Strategy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Randstad Technologies
Blackberry Developer - €45,000 - €50,000 – The Hague Leading mobile application development Company is looking for a talented senior software developer to join the mobile software engineering team to design and develop the next ... more >
| Evolution Recruitment Solutions
IT Development Manager - .Net, C#, embedded C, SQL. This is a new position to take ownership of UK focused software development projects. Core responsibilities will be delivering new software solutions, identifying development requirements, managing ... more >
| Computer People
Working for an award winning technology company based in Birmingham, Computer People are looking for 2 Java Software developers to join them in brand new positions. The role will involve end to end analysis and ... more >
| Computer People
Computer People Nottingham are recruiting for a local firm who are experiencing great success within their industry sector. With long-term growth plans, business is booming hence the need for a new Lead Software Engineer skilled ... more >
More job opportunities