About
Subscribe

Why breaches are rampant - 10 facts from RSA

Admire Moyo
By Admire Moyo, ITWeb news editor
Johannesburg, 28 Feb 2012

The RSA Conference 2012 kicked off today in San Francisco with everyone questioning the credibility of the industry following last year's widespread breaches that did not even spare RSA, the security division of EMC.

However, RSA, in conjunction with Carnegie Mellon CyLab, in their third survey on how boards and senior executives are governing the privacy and security of their organisations' , say senior leadership in organisations are out of touch as far as corporate security is concerned.

Jody Wesby of Carnegie Mellon University, addressing the press, said companies are leaving themselves wide open to attack if they do not have a chief information officer and a chief information security officer to protect their assets.

In the study, the company surveyed the Forbes Global 2000 companies' boards and senior management and found:

1) Today, cyber attacks have moved to a new level - corporate data is at a higher risk of theft or misuse than ever before.

2) The systemic nature of recent attacks has alarmed both industry leaders and government officials around the world.

3) Boards and senior management still are not exercising appropriate governance over the privacy and security of their digital assets.

4) Although it has long been recognised that directors and officers have a fiduciary duty to protect the assets of their organisations, this duty now extends to digital assets, and it has been expanded by laws and regulations that impose specific privacy and cyber security obligations on companies.

5) Among the Forbes Global 2000 companies, when it comes to board reviews and approvals on top-level policies regarding privacy and IT security risks, 42% rarely or never review or approve top-level policies on privacy and IT security risks; 28% do so occasionally, while only 23% do it regularly.

6) Sixty-six percent of respondents review and approve roles and responsibilities of lead personnel responsible for privacy and IT security; 18% do it occasionally, and 19% do it on a regular basis.

7) Only 28% of boards surveyed review and approve annual budgets for privacy and IT security programmes; with 10% doing it occasionally, and 54% rarely doing so.

8) A quarter of the boards regularly receive reports from senior management regarding privacy and IT security risks.

9) CISOs or CSOs do not get the attention of their senior management and boards, and their budgets are inadequate.

10) Some 58% of the respondents said their boards did not review the organisation's insurance coverage for cyber-related risks, compared with 65% in 2010.

Share