SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Case Studies and Best Practices From Canada and Internationally

Half of UK financial firms not ready for compliance

Half of UK financial firms not ready for compliance

By:  Computerworld UK staff  On: 07 Aug 2007 For: ComputerWorld U.K. Creator

More than half (51 per cent) of all U.K. firms have not implemented the security processes to comply with legislative directives such as PCI and MiFID, says a report.

More than half (51 per cent) of all U.K. firms have not implemented the security processes to comply with legislative directives such as PCI and MiFID, says a report.

Many U.K. financial firms are not ready to meet compliance goals and IT staff are sceptical about the understanding of IT security amongst the board.

These are the key findings of a survey of 218 security and IT managers from financial firms about their company's readiness and views on compliance and risk management found. In fact, 40 per cent claimed that the board were merely paying lip-service to IT security to gain compliance status.

The survey, conducted by EMedia on behalf of NetIQ, said there is a lack of coordination between the IT organization and the rest of the business.

Almost a third, 29 per cent, of IT security managers said their company's security policies were not closely aligned with its business objectives or areas of risk within their organization. Further, 57 per cent of them claimed that internal staff didn't understand the legislation that affected their business.

Industry analyst Thomas Raschke of Forrester Research echoed the finding that there is a lack of understanding between IT and the rest of the board and user community.

In the recent Forrester report, 'What's top of mind for European security managers?, Raschke says the focus of chief security officers (CSOs) and chief information security officers (CISOs) has shifted from technology to business risk management.

Raschke said: "We are currently in a time of transition, one that can make CISOs with less business-side experience acutely uncomfortable. In the interim, legacy CISOs and other security managers still struggle with gaining visibility and influence within the business."

Ulrich Weigel, director of security products for NetIQ, said: "This reinforces the need for the CSO to be not only a technologist but also a good communicator, who is able to interact with people outside of the IT department. We see many misconceptions about the importance of risk management in the market place. Successful companies are beginning to realize that security management is about more than buying a bunch of different security technologies and deploying them. IT and security managers must ensure that the policies and procedures are relevant and integrated with their company's business and objectives."

Weigel added CSOs must communicate at a senior board level that security is no longer just a cost item because it can "differentiate them from competitors and win them new business."


Sign up for our Newsletters












Print |  Views: 535   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Computerworld UK staff Computerworld UK staff is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Xbox Live exec leans on his security background
Xbox Live exec leans on his security backgroundA Microsoft executive tells the SecTor 2008 crowd how to get every business unit thinking about protecting data without shelling out big bucks on new training and services
Security group releases business-relevant metrics
Security group releases business-relevant metricsThe Center for Internet Security will make its metrics available as a community resource and will include ways of measuring vulnerability assessments and time to recover from security incidents. How you can use these metrics to improve your company’s security
Ten gotta-have-'em IT skills employers want now
Ten gotta-have-'em IT skills employers want nowBusiness initiatives such as enterprise mobility, data center consolidation and unified communications are driving demand for expertise in new technology areas and reinforcing the importance of mastering the fundamentals
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof
blog comments powered by Disqus