About
Subscribe
  • Home
  • /
  • Computing
  • /
  • Sanlam uses CS Holdings` training as defence in battle for IT security

Sanlam uses CS Holdings` training as defence in battle for IT security

By IT Public Relations
Johannesburg, 20 Sept 2001

IT security has become a hot issue in business, and many companies are increasingly at risk to hackers, viruses, industrial espionage and other threats. Sanlam has taken a proactive stance to this issue by appointing CS Education Solutions, a division of JSE-listed CS Holdings, to provide general security protocol training to its Personal Finance division. CS Holdings` training for Sanlam was conducted over a four-month period, for 3 900 users.

"Sanlam realises that in order to protect its clients from security outbreaks, it has to inform its staff of what constitutes good security practice," says Owen Henry, Sanlam account manager at CS Education Solutions. "Consequently, we developed training material based on Sanlam`s current general security protocols, adapting it to suit their existing policies, systems and procedures.

"The training was specifically geared to increasing awareness among employees of everyday security procedures that a skilled user would generally take for granted," he continues. "We also briefed management on how to identify security risks within the organisation. Additionally, we provided insight to the top executive on the extent of damage that can be inflicted on an organisation, its clients and suppliers if these protocols are not followed, and the financial impact this could have on the company as a whole."

Henry says many companies are unaware of how vulnerable they are to security attacks. "For example, it is relatively simple to develop a virus. Accessing a company network is also child`s play for the seasoned hacker. We sketched several possible security breach scenarios for Sanlam, outlining steps to take to prevent an attack and how to solve it should they become victim to one."

The International Data Corporation (IDC) believes that security must be a consideration at every step of the development process of a business strategy. Best-practice security also demands regular attention to stay on top of the stream of new vulnerabilities that appear almost daily. Much of this process includes the use of security technologies, but a fair amount also includes making sure business processes and security policies are complementary. Perhaps the biggest problem with security is that it can appear to be too complex due to the fact that some level of security is required at every level of a system.

Current IDC research shows over 75% of companies spend less than 10% of their IT budget on security initiatives. According to the IDC, the explosion of e-commerce, forecasted to be worth $1.6 trillion by 2003, is offering organisations of every size opportunities previously unheard of. The potential customer base from the Internet is growing dramatically - from 327 million online users in 2000 to 600 million users in 2003. According to IDC`s findings, organisations must open up their systems to unprecedented levels of users. However, they must also invest more in IT security.

Pim Bilderbeek, vice president at IDC, said: "In the past, attitudes about security have been based on the cost of installation, offset against the likely negative cost of a security breach. However, as market dynamics change between an organisation, its partners, customers and employees, the business pressure to extend online access suggests that security actually enables new kinds of business processes."

Bilderbeek continued: "We believe enlightened organisations are beginning to regard the security of their systems not as an insurance policy, but as a competitive advantage. This is the right approach if businesses are to take full advantage of the new market dynamics brought about by e-business. By creating trusted business platforms, an organisation can maintain high degrees of flexibility and launch new initiatives very quickly, without being constrained by poor security."

Research group Gartner reports that all enterprises must protect crucial computer networks and data using a cohesive intelligent strategy based on appropriate levels of information security policies, products and procedures. The minimum standards are: Firewalls; the use of intrusion detection technology; data and e-mail encryption; and strict monitoring of user activity.

Share

CS Education Solutions

 

CS Education Solutions, a division of JSE-listed CS Holdings, is one of the largest providers of high-quality, customised, and accredited IT education and training solutions to corporates and end-users in the Southern African region.

Editorial contacts

Ivor van Rensburg
IT Public Relations
(012) 361 7340
ivor@itpr.co.za
Owen Henry
CS Holdings
(012) 947 2947
ohenry@cs.co.za