About
Subscribe

SA security systems out of touch?

Johannesburg, 31 May 2012

Though there have been plenty of breaches reported worldwide, South African companies are confident that their existing security is sufficient.

This is one of the key findings of the ITWeb-RSA Security Survey which ran for online for two weeks, attracting 132 responses. RSA is the security division of EMC.

Asked what prevents or delays investment in IT security within their organisations, the majority (32.23%) said they were convinced that their existing security solutions are adequate.

Nonetheless, 22% blamed lack of security from top level, while 17% pointed to lack of security management tools. Meanwhile, 15% revealed that it is too difficult to determine ROI or to justify costs.

Stephan le Roux, the district manager of RSA Southern Africa, says many organisations seem to believe they have sufficient security when this is not the case, as has been proven by the recent security breaches which have happened worldwide.

“The reality is that hackers are well-funded and staffed, with vast resources. The threats are, therefore, continuously evolving and it is critical that organisations remain cognisant of the new forms of attack.”

Security budgets

Most of the respondents (44.63%) are unsure about their investment in security as a percentage of their IT budget, the survey also discovered. Some 14% noted that the security investment is less than 2% of the total IT spend while the same percentage noted that it ranges from 2% to 5%.

, and what reputational damage could be suffered.

“By elevating information security to board level, it can be clearly defined in the IT budget. Every organisation is different, so the right balance needs to be achieved to meet particular needs.”

Meanwhile, the study also determined that information security is critically important to most organisations (63.37%).

According to Le Roux, information security is critical because organisations stand to lose intellectual property, competitive corporate information, customer identities and more.

“We are operating in a global village, and information security attacks can come from anywhere in the world. Information security, therefore, needs to be a boardroom topic and, because the threats change so frequently, companies need to be agile in implementing their defences.”

Compliance motivation

Compliance is the biggest driver of IT security investment within organisations, the survey also found out. Some 57% of the respondents noted that they invest in IT security to ensure compliance; while 52.07% said IT security investments are being motivated by external threats excluding malware.

According to Le Roux, compliance is necessary, and it's starting to have a bigger impact in SA. However, he points out that getting an organisation's systems to the point where compliance can be demonstrated does not automatically mean the organisation's information is secure.

He notes that new legislation is driving higher levels of security compliance; and meeting those requirements is an effective, measurable way of implementing best practices and information security systems.

Most organisations (37.87%) are compliant with ITHL, the survey also determined. Some 24.32% also noted that they are compliant with King III; as well as Corbit (19.8%).

Commenting on this finding, Le Roux says, like King III and Corbit, ITHL is a framework which guides the operations of an organisation by recommending the use of best practices to ensure that good processes are in place. ITHL is popular because it helps organisations to follow good processes which can be accurately measured, he adds.

Network security

Asked about their organisation's medium-term investment priorities in IT security, the majority (61.26%) cited network security; followed by data security (57.66%); identity and access management (51.35%); and malware prevention and protection (50.45%) among others.

Companies are building bigger networks and using them to distribute more and more information, Le Roux explains.

“Protecting the information floating across the network is a major challenge. It's vitally important to ensure that the wrong information doesn't leave the organisation via e-mail, for example. I believe this aspect of information security will become even more of a key focus in the future.”

Most of the organisations (64.86%) have done an internal IT risk evaluation of business continuity and data loss or corruption, it also emerged. This was followed by 54.95% who have evaluated external attacks including malware, attacks on network and systems.

It was also discovered that the majority of the respondents (60.36%) do regular assessments to evaluate risks. On the other hand, 56.76% said they implement security whenever they identify a potential risk. Meanwhile, 29.73% revealed that their organisations train all employees to address risks.

“I believe this type of survey is important because it provides an accurate indication of the South African market from an information security perspective. It tells us where we are going, and what we need to be thinking about,” Le Roux says.

“The trends in SA could differ to those in the US or UK, so we need to know what's happening locally - and in fact, it's the only way to plan ahead. Information security and the prevailing threats are constantly evolving, so organisations need to remain vigilant. This survey helps by providing insight into what to do next,” he concludes.

Share