Sunday, November 14, 2010

Emerging technology trends increase risks of protecting corporate information

An increasingly mobile workforce, cloud computing and social networking all pose significant threats to organizations’ information security programs, according to the 13th annual Ernst & Young Global Information Security Survey. The report indicates that while there is a commitment to protecting data, organizations still face advanced, persistent threats that jeopardize the traditional corporate umbrella.

The report is based on a survey of nearly 1,600 senior executives in 56 countries and takes an in-depth look at the challenges organizations face when it comes to current trends, new technologies used by their workforce and the difficulties of trying to protect information while operating in a virtual business environment. As these changes bring new risks, the survey also examines how organizations are adapting and addressing their information security needs. The results show that 60% perceive increased risk from the use of social networking, cloud computing and personal mobile devices at work. Additionally, 64% of respondents see data protection as one of the top IT risks that has escalated in the current environment.
Additionally, businesses no longer view information security management programs as insurance policies to be used only in the event of a disaster.

Managing the mobile workforce
The proliferation of a mobile workforce has put employees on the front line of information security. According to the survey, respondents view the most serious risk associated with mobile computing as the potential loss of business information; 52% see the use of personal devices as the main cause of data leakage. In addition, 53% of respondents indicate that workforce mobility is a considerable challenge to delivering information security solutions effectively. The majority of respondents (92%) also view employee awareness of security as a challenge, as the demands of an increasingly mobile workforce change the way companies support and protect the flow of information.

Information security at a cost
Overall, organizations recognize the risks that come with emerging technology trends and are taking steps to protect information with stronger information security programs. In fact, half of those surveyed plan to increase their spending on data leakage/data loss prevention efforts over the next year.

But, while spending will increase to protect data, many organizations still feel pressured to reduce IT spend in other areas, leading them to look externally for efficient solutions. Despite an unproven track record, 45% of organizations are currently using, evaluating or planning to use cloud computing services within the next 12 months. The risks associated with cloud computing include data leakage, with 52% identifying it as the largest associated risk, followed by 39% who cite the lost visibility of company data as an increased risk of cloud-based solutions.

However, most respondents (85%) indicate that external certification of cloud service providers would help to evaluate security controls and increase trust.
Evidence also suggests that few organizations have fully assessed the risks associated with social networking. Just one-third report that social media presents a considerable information security challenge and only 10% say examining new and emerging IT trends is a very important information security function.

Plugging the leak
The focus in information security is shifting from a technology-only approach to a technology and people approach, as information security becomes an expanded function of which all employees are aware of and have a responsibility to adhere to. Without clearly defined and communicated security policies on the use of new technology, organizations’ exposure to risk will increase.

More information on technology trends can be found at www.SupportIndustry.com.

No comments: