Security protects bottom line

By P.J. Connolly, InfoWorld |  Business Add a new comment

COMPUTER SECURITY means different things to different people. To someone trained in physical security concepts, the computer is secure as long as it's behind a locked door. To a system administrator, security depends on installing the patches for known security holes in the applications and the OS. To your customers, security means that personal or sensitive data won't be available to every 15-year-old with a Linux box and some hacking tools. But no matter your perspective, one thing is for sure: Security is going to be an IT hot button for as long as computers are networked.

The cost of beefing up security may seem like a tough sell during the current economic downturn. But companies that fail to ensure security may not be around long enough to learn from their mistakes. After all, the true cost of a security breach is not the overtime your emergency response team racks up or the potential fines and litigation expenses; what really hurts is the loss of confidence and goodwill that follow.

Preventing security issues from knocking your business for a loop isn't easy, but it doesn't have to be overwhelming either. Rather than tackling everything at once, the best strategy is to determine where the greatest vulnerabilities are and address those problems first.

Securing your network

BUSINESS CASE

With many enterprises facing tighter budget restrictions, it's not uncommon for network security to fall off the list of IT priorities. But the cost of an unauthorized breach can quickly outstrip the expense of upgrading existing security. And as the number of telecommuting workers increases, the risk of successful hack attempts also rises.

TECHNOLOGY CASE

Securing your network means locking down physical resources, monitoring remote users, and keeping a close eye on your physical network -- no small task. The good news is that security tools are getting better all the time. Interesting developments in the fields of intrusion detection and biometric monitoring will tighten network and system security in the near term.

PROS

+ Customers are more likely to do business with a vendor whose security is top-notch

+ Securing networks and systems can prevent business interruptions and lost productivity

CONS

- Security enhancements often divert resources from other projects

Start with the basics

There's an old saw in the IT business that the only completely secure system is one that is disconnected from a network, encased in concrete, and lying at the bottom of the ocean. Because that's an impractical goal for most of us, the next best thing is to ensure that your systems are protected at a level that befits the data on tthem.

Obviously, security starts at the physical level. Your gear may be housed in the strongest bunker since Hitler's Chancellery, but there's more to security than gates, guards, and guns. Knowing who goes in and out of the server room -- and when -- is the difference between controlling access and simply handing out badges.

Remote offices and telecommuters sometimes offer weak spots to hackers. There is little point in building a corporate data fortress if you're going to leave it open to a server stashed in an unlocked closet in Peoria. The unsecured home computer of an employee whose work follows him or her home is an even greater hazard, as we saw during the Microsoft "QAZ" incident earlier this year. Of course, these folks are your co-workers, and you can't string them up first and ask questions later. But remote workers should know that their privileged status means they must pay more attention to security basics than the ordinary cubicle rat does.

If your shop is like most, the IT operations staff handles tasks such as data backup and disaster recovery. But that doesn't relieve the security manager from responsibilities in these areas. And disaster recovery and incident management plans are good things to have, but only if you rehearse them regularly.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    BusinessWhite Papers & Webcasts

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Ten Steps to an Enterprise Mobility Strategy

    Enterprise employees are more mobile, relishing the ability to work productively anywhere, at any time. They may use any means to get connected, often creating financial and security risks for your company. Discover how to get control of your enterprise mobility strategy and ensure mobile worker productivity with these ten steps.

    White Paper

    What You Need to Know About the Costs of Mobility

    Mobile workers want to get connected anywhere, at any time, often at any cost. Enterprise mobility is often a hidden "black" budget in your company. Ensure that your traveling employees are productive everywhere, even while you control cost and security, through an enterprise mobility strategy.

    White Paper

    The 2011 iPass Mobile Enterprise Report

    This industry survey covers trends, recommendations and a policy guide on managing Enterprise Mobility for IT management and CIOs. Get data on employee device liability, as well as smartphone/tablet penetration, budget control and provisioning. Find out how your organization compares, how to ensure mobile worker productivity, and control costs.

    White Paper

    Smarter Commerce is redefining value chain visibility

    Smarter Commerce is redefining the value chain in the age of the customer. It starts with putting the customer at the center of your operations - which of itself is not a new idea - however, truly operationalizing this strategy is not easy.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question