Big Data. Big Decisions
InformationWeek
Special Coverage Series

Commentary

Rob Preston

Rob Preston

VP & Editor in Chief, InformationWeek

Down To Business: It's Past Time To Elevate The Infosec Conversation

At the RSA conference, the security discussion was about helping customers innovate and deliver business value.

The RSA Conference, the annual security fest hosted by EMC unit RSA, is to the information security industry what the New Hampshire primary is to the presidential election process: the first major venue for the leading players to set the tone and frame the discussion for the coming year.

Last year, RSA chief Art Coviello championed industry consolidation, arguing that as a handful of major vendors (EMC, Cisco, IBM, Microsoft) built security into their infrastructure platforms, standalone security challengers would fall by the wayside--all within three years. "If I'm proven wrong about the timing," Coviello said last year, "I won't be proven wrong in the need for this." The likes of Symantec and McAfee begged to differ, and the industry continues to debate the strengths and weaknesses of all-in-one security architectures.

RSA, as host vendor, sought to exploit its home turf advantage again last week, when Coviello struck a different tone. Instead of focusing on industry restructuring and technology architectures, he elevated the security discussion to one about helping customers innovate and deliver business value.

More than 80% of the IT, security, and business executives RSA recently surveyed with IDC "admit that their organizations have shied away from business innovation opportunities because of information security concerns," Coviello told the RSA audience. The main challenge: Move the internal conversation about security away from fear mongering and worst-case scenarios toward how security can augment new products and services. Or at least don't get in the way. It's tantamount to the security pro's Hippocratic oath: First, do no harm.

While RSA offers no elixir for making security a "business enabler," it has created a Security for Business Innovation Council to get security pros talking about the issue. RSA quotes member David Kent, VP of security for biotech company Genzyme: "If you are doing your job, you shouldn't even sound like a security person. The business doesn't care how many viruses you stopped. ... 'How are you helping me meet my business objectives?'"

Likewise, InformationWeek contributor Greg Shipley, CTO of security consultancy Neohapsis, urges security pros to integrate risk management into all processes. They also need to get better at understanding and relating to their internal audiences, assessing which data to assign the most protection, and picking their battles and technologies more carefully. "For some organizations," Shipley writes, "this will require a wholesale transformation."(See Risk Management: Do It Now, Do It Right.)

It's still early in this evolution. When asked last year how their companies measure the value of their security investments, the 1,100 U.S. respondents to InformationWeek's Global Information Security Survey offered a stew of mostly operational criteria: 43% said they measured value in terms of reduced worker hours spent on security; 33% measured it in reduced breaches; 33% in reduced network downtime; and 24% in reduced incident response times. With the exception of improving intellectual property protection (27%) and honing risk management strategies (25%), none of the criteria selected relates to business value. In fact, 24% of the respondents didn't measure the value of their security investments at all.

The sooner security pros can converse in the language of risk mitigation and business opportunity, the more they'll be involved in strategic planning and the less they'll be considered a cost center.

Compare Coviello's nuanced approach to the classic fire and brimstone of Homeland Security Secretary Michael Chertoff, who at RSA last week warned that a large-scale cyberattack on the United States could inflict damage comparable to the Sept. 11, 2001, terrorist attacks. Chertoff likened U.S. government efforts to improve cybersecurity to the Manhattan Project, which developed the atomic bomb.

Chertoff has his own unique war to fight; enterprise security pros may want to use Manhattan Project metaphors sparingly.

Rob Preston,
VP and Editor in Chief
rpreston@techweb.com

To find out more about Rob Preston, please visit his page.



Related Links

Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.