SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Following regs doesn’t mean enterprise is secure: Study

Following regs doesn’t mean enterprise is secure: Study

By:  Nestor E. Arellano  On: 07 Mar 2013 For: Computing Canada Creator
 

Conclusion is one of many revealed by security executives of Canadian businesses interviewed in a recent Telus-Rotman survey

Despite growing pressure on enterprises to comply with increasing government and industry security regulations, a majority of Canadian businesses believe falling into line doesn't make an organization secure.

“According to participants, complying with government and industry regulations is the minimum level of security required,” authors of the 2013 Telus-Rotman IT Security Study. “Compliance does not constitute the necessary level of security required in a landscape characterized by targeted, advanced threats.”

“Being compliant is not necessarily being secure,” the study quoted one participant as saying.

That observation underscores the widespread insecurity felt by many security leaders in organizations across the country who are struggling to deal with issues such as targeted attacks, data leaks, insider breaches, cloud technologies and the bring your own device trend.

In the fall of 2012 the Rotman School of Management at the University of Toronto and Telus Security Solutions held a series of round table discussions and one-on-one interviews with director level security decision makers in Vancouver, Calgary, Toronto, Ottawa and Montreal to gain insights into their security concerns and strategies. Rather than statistics, the report provided perceptions and quotes from the participants.

Among other things, authors Walid Hejazi, associate professor of business economics and academic director at Rotman, and Hernan Barros, director of product management at Telus, focused on what kept senior security leaders awake at night; how they handle the BYOD trend, the impact of legislated compliance and the emergence of new technologies.

The study found that senior security executives have four key security-related concerns:

- Has my organization been breached and I don’t know about it?

- How will the breach affect my brand?

- What are my employees doing with corporate data?

- How do I retain my security resources?

It’s almost a foregone conclusion for many of the respondents that their organization will be breached, according to the findings. This inevitability appears to be summed up by one participant who was quoted as saying: “When I started this job, I told my senior management that we will be breached within the next 18 months, so get over it now.”

RELATED CONTENT


Sign up for our Newsletters

 












Print |  Views: 2041   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




nestor e. arellano Nestor E. Arellano  – Newswire Specialist Nestor edits and posts newswire content for ITWorldCanada’s online publications and e-newsletters. Nestor joined ITWC in 2006 as a senior writer an... more

Recent Canadian IT Jobs




blog comments powered by Disqus