Gartner: Security costs fall with good policies

Enterprises increasingly will face skilled IT criminals trying to infiltrate corporate networks for sensitive data stored in databases, but adopting new policies to evaluate risk should help drive the cost of defense down, computer security analysts said Monday.

The attacks could come in a variety of forms -- extortion attempts after data is encrypted and held hostage; the theft of intellectual property -- but all could have "potentially disastrous" effects for unprepared businesses, said Vic Wheatman, managing vice president at Gartner.

"Most businesses aren't attacked, but some are," Wheatman said at Gartner's IT Security Summit. "We believe that cybercrime represents the next wave."

Businesses will need new IT strategies to defend themselves. Enterprises now should spend 4% to 6% of their IT budgets on information security. This figure is equivalent to what organizations allot for casualty insurance, he said. From its latest data, Gartner expects information security budgets to increase 4.5% during the next year.

Many corporations are creating security policies based on government regulations rather than threats, however. The result is policies that meet auditors' requirements but aren't necessarily best for overall security, said Jay Heiser, Gartner research vice president. "We refer to that as 'regulatory distraction,'" Heiser said.

Rather than trying to anticipate a new regulation, it's better for companies to treat regulation as one more factor in an overall risk portfolio, Heiser said. It could take at least five years for an enterprise to form this approach, he said.   


The IDG News Service is a Network World affiliate.


« Previous | 1 | 2 | Next »

Recent News:
· Feds draw a bead on Russian behind Mega-D botnet
· Ransomware Attack Resurfaces to Hold Files Hostage
· Adobe Reader X Makes PDF Files Safer
· PayPal Users Beware of Holiday Phishing Scam
· McAfee Reports Malware at All-Time High