Study: Company execs admit IT idiocy

By Matthew Broersma, Techworld.com |  Security Add a new comment

Most of the world's top executives now consider security the single most important issue for their corporate networks. While at the same time nearly four in five admit they open email attachments from strangers.

It's as if the perfect sysadmin survey has been produced. Company execs idiots, official. But then anyone who has been in charge of a company network will not be entirely surprised.

The survey from the Economist Intelligence Unit Ltd. (EIU), backed by AT&T Corp. and published on Wednesday, found that security was the top network-related issue for 78 percent of the 254 senior executives who responded.

Respondents ironically say most of the problems were caused by employees, estimating that 83 percent of attacks were initiated internally, from sabotage, espionage or mistakes. Despite this, 78 percent of the idiots admitted to having clicked on an email attachment from an unknown person within the last year, a figure the EIU found "astonishing".

Such blunders have helped to drive the cost of network attacks from US$3.3 billion in 1997 to $12 billion last year, according to Computer Economics figures cited by the EIU. This is driving security spending to rise faster than overall IT spending. On average the execs spent nine percent of their IT budgets on network security in 2002, rising to 11 percent last year and expected to hit 13 percent this year.

Executives are aware that their networking priorities -- such as giving remote workers access to the network and making customer and financial data available to employees -- are inextricably linked to security problems. More than 80 percent of executives admitted their goals left their firms vulnerable or extremely vulnerable to threats.

Security spending is moving from perimeter protection and intrusion detection to better tools for preventing attacks and recovering when they happen, executives said. Thirty-two percent said they already used or planned to use managed security services in the next two years, with another 14 percent saying they would use them in the long term. However, most of these companies (70 percent) are small and medium-sized firms.

The survey found that CEOs are increasingly taking responsibility for network security policy, while some companies are beginning to appoint a chief security officer, a move applauded by AT&T. "For any company, it is virtually impossible to ensure protection of assets without one person owning the focal point," said Ed Amoroso, information security officer at AT&T, in a statement.

Security moved up from its No. 2 position in last year's survey, when reliability and availability were the biggest concern.

The online survey canvassed 254 senior executives, with 40 percent of respondents from Europe, 27 percent from North America and 21 percent from Asia-Pacific, mostly representing the financial services, professional services, manufacturing, transportation and energy sectors. It was supplemented by in-depth interviews with executives and analysts. The research took place between March and April of this year.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question