Visibility of information security exposure is increasing; however, alignment of IT security to business objectives stays limited
International study by PricewaterhouseCoopers, CIO and CSO Magazines shows
signs that the role of Security is maturing but critical deficiencies remain
The European organizations are not yet fully compliant with the increasing local and global regulations, according to “The Global State of Information Security 2006”, a worldwide study by CIO magazine, CSO magazine and PricewaterhouseCoopers. The survey, the largest of its kind, represents the responses of almost 7,800 senior executives at companies in more than 50 countries across all industries. The importance of security becomes more visible within the business boards, but the alignment of security strategy to business objectives is still limited. These findings are confirmed when analyzing the IT security budget evolution: the IT security investments are increased in technology rather than in the alignment and enforcement of security policies. Moreover, benefits of IT security investment are not yet measured fully.
“Belgium is overall in line with EU average, although some additional work should be done in SOX compliance (for those where it applies) and in building objective benefits measurements of security spending,” says Daniel Evrard, IT Management Partner responsible for ICT Process Improvement within PricewaterhouseCoopers Belgium.
Effects of regulations and compliance
Both European organizations and their international colleagues continue to struggle with applicable information security laws and regulations that govern their industries – particularly those in the area of privacy. Of those EU respondents stating that they were noncompliant with applicable regulations, 45 percent are not compliant with the European Union (EU) Data Privacy Directive (38 percent for Belgium) and 17 percent report that they are still not in compliance with Sarbanes-Oxley (29 percent for Belgium). Thirty-six percent of all EU respondents (29 percent for Belgium) are noncompliant with other state/local privacy regulations.
The struggle to meet compliance requirements extends beyond Europe, with a high percentage of non-European firms reporting similar challenges. Eighteen percent of the US-based respondents are non-compliant with California Security Breach Notification Law CA 1386; half of the Australia-based respondents report not being in compliance with Australian Privacy Legislation.
“There is a marked lack of enforcement of these laws and regulations, and the cost of non-compliance is currently not as high as the expense of complying. To improve compliance with these regulations, security laws need to have more meaningful repercussions,” says Sebastian D'Amore, Eurofirm IT Security Partner, PricewaterhouseCoopers. “Additionally, companies need to enforce compliance with their own security policies. This is one of the most critical factors for reducing network downtime, and yet respondents report that only a little more than two-thirds of all users are compliant – a statistic that has remained unchanged over the past three years.”
Some signs of information security maturity
Survey findings show several signs that the role of security is maturing. This year’s survey reveals that 38 percent of respondents (38 percent worldwide; EU: 44 percent; BE: 47 percent) have been in their jobs for five years or more, indicating that security positions are becoming established within most organizations. Furthermore, security executives appear to be moving up the reporting chain, with security heads most frequently reporting to the CIO (33 percent worldwide EU: 30 percent; BE: 38 percent), CEO (31 percent worldwide EU: 26 percent; BE: 33 percent) and the company board (24 percent worldwide; EU: 32 percent; BE: 27 percent)
Despite positive steps, survey responses also reveal critical deficiencies. Only 37 percent of Belgian respondents report having an overall security strategy in place – exactly the same percentage that reported this last year. In addition, while senior security executives are moving up the organizational ladder, the number of organizations hiring CSOs and CISOs has stagnated. Sixty-six percent of respondents (EU: 61 percent; BE: 48 percent) have yet to hire a CSO or CISO (compared to 60 percent in 2005).
Alignment of security to business objectives
Findings show limited improvement in organizations’ alignment of security to business objectives. Only 28 percent of respondents (EU: 27 percent; BE: 26 percent) report that their security policies are completely aligned with business objectives (slightly up from 26 percent in 2005). Moreover, in Europe, 40 percent of the respondents (BE: 38 percent) admit that more than half their users are not in compliance with their information security policies. This is not the case in the US, where only 19 percent of the respondents observe that half of the users are not compliant.
IT security budgets
Almost half of the survey respondents (46 percent) (EU: 39 percent; BE: 37 percent) indicate that their IT security budgets will increase this year, with more than one out of five saying the rate of increase will be in the double digits – a faster increase than the overall IT budget.
Survey results also show the ability to prove that ROI remains a challenge. Today the measure of the effectiveness of security is mainly based on the “professional judgment” (worldwide at 46 percent; EU: 37 percent and BE: 38 percent) and on the “risk reduction score” (worldwide: 32 percent; EU: 31 percent and BE: 30 percent) than “ROI” (worldwide: 25 percent; EU: 20 percent and BE: 15 percent).
Top three priorities in IT security
The third annual survey also shows a noticeable shift in priorities. In 2006, IT executives in Europe and in Belgium listed the top three priorities on their to-do list as technological fixes including data backup, network firewalls and user passwords. This is a departure from 2005 when the number one priority was disaster recovery and business continuity, followed by employee awareness and training programs, and with data backup third on the list.
“For information security to be most effective, organizations must align their security policies and spending with their business process. Organizations that do this, experience fewer financial losses and experience less network downtime than those that do not,” says Sebastian D'Amore.
Confidence lacking in third-party security measures
The level of confidence in security measures has risen slightly from last year, with 33 percent (EU: 35 percent; BE: 47 percent) reporting that they are very confident in their own organization's security (up from 28 percent in 2005). Likewise, the perception of the CEO's level of confidence is up slightly with 39 percent (EU: 37 percent; BE: 43 percent), indicating that they are very confident as compared with 35 percent last year.
However, many organizations rely on third parties for various business reasons – including outsourcing arrangements of financial, HR and IT functions – which in turn impacts the effectiveness of their own organization’s security measures. Of those who use third parties, only 22 percent (EU: 27 percent; BE: 35 percent) report that they are “very confident” in their partner/supplier’s security.
India still needs to close their security gap
This year's survey uncovers some major deficiencies in security measures for organizations responding to the survey from India. As India continues to make enormous gains in the world economy, the security infrastructure is clearly lagging behind.
As a result, extortion, fraud and intellectual property theft occurred last year at one in every five or six India-based companies — rates that are double and even quadruple those of the rest of the world.
Despite the lag in security practices, the survey findings show some positive signs that India is proactively working to remediate the gaps. India-based companies are outspending other nations on information security, with 70 percent of India-based respondents indicating that they have increased security spending since 2005 (vs. worldwide: 46 percent).
Industry-specific highlights
The section hereafter presents the specific highlights per industries. These highlights are based on the worldwide results of the security survey.