During the opening keynote at RSA Conference 2012, in London, Art Coviello, executive chairman of RSA, encouraged an intelligence-driven model for ICT security.
He cited several reasons why conventional thinking on security should be challenged, including the shortage of ICT security skills, not enough understanding and co-operation on security issues between countries and organisations, as well as 'budget inertia'.
Saying these factors are holding security back, Coviello added that most security spending (80%) is allocated towards prevention, 15% to detection and monitoring, and only 5% towards response.
He said in an era of connectivity and openness, where breaches are almost expected even among the best-defended businesses, this spend needs to focus on quick detection and response.
Unless this happens, he said it is nearly impossible to detect sophisticated attackers quickly and with enough detail and accuracy to launch an effective defence.
Coviello said a perimeter is an easy target, and as attacks within the perimeter become more sophisticated, only equally sophisticated detection capabilities and analytics can enable a response that is quick enough to help avoid loss.
Another major stumbling block to preventing the threats out there is a lack of co-operation between organisations and governments, he explained. "In addition, a broad lack of understanding among these governments, media, consumers, and private and public organisations put the security industry at a major disadvantage."
Coviello discussed several key issues, which he said will help the industry fight threats more effectively. Firstly, he cited a shift towards intelligence-based security, an approach that advocates evaluating risk from both the inside out and the outside in, looking at risk in the context of vulnerability, probability and materiality.
"In accordance with this, re-evaluate budgets and balance spending priorities accordingly."
Secondly, adopt a layered defence. "This must focus on controls that deliver the situational awareness, deep visibility and environmental agility to deter, detect and defeat sophisticated targeted attacks - a layered effect as it were."
Thirdly, the right skills are vital. "Value should be placed on security analytic skills over capabilities in traditional security or IT infrastructure management; don't waste good skills on mundane tasks."
Finally, co-operation. Develop an ecosystem of governments, vendors and user companies that collaborate to grow trust and share knowledge.

