Period of reckoning for the IT security industry
Period of reckoning for the IT security industry
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

IT security industry faces a tough 2005

Days of wine and roses over as corporates streamline security budgets

Iain Thomson at the RSA Conference in San Francisco, vnunet.com 16 Feb 2005
ADVERTISEMENT

This year will mark a period of reckoning for the IT security industry as spending begins to decline, Gartner has predicted.

Victor Wheatman, managing vice president at the analyst firm, told the RSA Conference in San Francisco that by 2006 security spending will have dropped to four or five per cent of corporate IT budgets. In more efficient companies it could drop lower with no harm to the level of protection, he claimed.

"It is a myth that the more you spend on security the more secure you are," said Wheatman. "2005 will be the year of reckoning for security spending. The lowest spending organisations, often the most efficient, can and will safely reduce spending to three or four per cent [of corporate IT budgets]."

The analyst suggested that the IT security industry is bedevilled by myths, including the belief that the more you spend the safer you are.

Wheatman added that it was erroneous to believe that regulation drives security spending, when in fact it is auditors who were most likely to insist on proper security set-ups.

The other key myth, according to the analyst, is that software is inherently flawed. Some IT buyers seem to accept that all software must contain errors and security flaws.

"You need to buy safer software for your applications," said Wheatman. "Software only has flaws if you buy code with flaws. Has anyone here taken part in that massive beta test of some software called Windows?"

He went on to outline those technologies which Gartner considers effective, and those that it does not.

Chief among the "must have" security items is 802.1x wireless authentication, enhanced firewalls that allow for deep packet inspection of data, and more intelligent networking technology that would check devices trying to join to see whether they were properly patched and virus free.

Other good buys included gateway antivirus and anti-spam checking, software that would perform security audits, and content filtering that blocks dangerous websites.

Physically locking down PCs within a company, and maintaining a proper business continuity plan, were also mentioned.

Of the technologies to avoid Wheatman's most surprising choice was biometrics. He maintained that hackers could beat such systems relatively easily, and that some companies which had installed biometric identification were now giving up and shutting down such systems.

Other security ideas getting the wooden spoon included default passwords, personal digital certificates and anything to do with quantum computing. He also ridiculed fads like paint that could apparently shield Wi-Fi emissions from buildings.

See also:

Strong sales as firms build security into the network at a hardware levelSecurity joins death and taxes as market soars in Europe  31 Mar 2005
Analyst prophesies time of reckoning  21 Feb 2005
Will companies improve security voluntarily?Tempers fray at RSA Conference as experts discuss government role in security  17 Feb 2005

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Leeds, United Kingdom | UKCRN
Application Development Team Leader, Leeds Part of the UKCRN IS Applications development team, you'll be responsible for leading the team behind a programme of IS developments to improve the IS environment for clinical research across ... more >
United Kingdom | University of East Anglia
Information Services Directorate, Computer Suite Technician £18,710 to £21,681 per annum Applications are invited for the role of Computer Suite Technician. The role holder will be part of the Computer Suite Team that is responsible ... more >
Chichester, United Kingdom | West Sussex County Council
  Testing Manager, Chichester, £42,222 - £45,090 (includes a Market Supplement, subject to review) The IT Testing function has until recently been performed within the project structure.  This new role recognises that we need to ... more >
United Kingdom | Sumisho Computer Systems (Europe) Ltd
Web Application System Engineer Sumisho Computer Systems (Europe) Ltd provide customers with a world of enhanced IT solutions. The role will involve maintenance of Oracle database server and web application server. The candidate must be ... more >
More job opportunities