Big Data. Big Decisions
InformationWeek
Special Coverage Series


IT Security Understaffing Worries CISOs

More than two-thirds of execs say current staffing levels pose risks to company safety, according to new study.

Who Is Hacking U.S. Banks? 8 Facts
Who Is Hacking U.S. Banks? 8 Facts
(click image for larger view and for slideshow)
More than two-thirds of the world's chief information security officers (CISOs) and other c-level executives report that their current information security operations are understaffed, and that it's compromising their company's security.

That finding comes from a new study released Monday by information security professional body (ISC)2, and is based on an online survey of 12,000 information security personnel, 14% of whom are C-level managers or officers, at the end of last year. The study was sponsored by (ISC)2 -- which counts nearly 90,000 members -- and Booz Allen Hamilton, and conducted by Frost & Sullivan.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Based on the survey, information security jobs are thriving and remaining relatively stable, with 80% of respondents reporting no change in their employment status or employer over the past year. Respondents with hiring power estimate that the number of available information security jobs will grow by 11% per year for at least the next five years.

[ Latest study echoes a Forrester survey from last summer. Read Security Skills Shortage, Or Training Failure? ]

Although 32% of organizations said they currently have the right headcount, and 2% said they have too many, 56% of respondents -- and two-thirds of C-level respondents -- said they currently have too few information security personnel. About 30% of respondents expect to increase their information security spending in the next year, but 12% expect it to decrease.

The top security threats seen by respondents are application vulnerabilities (69%), malware (67%), mobile devices (66%), internal employees (56%), hackers (56%), cloud-based services (49%), cyber terrorism (44%), contractors (43%), hacktivists (43%), trusted third parties (39%), organized crime (36%) and state-sponsored acts (36%).

Top worries about the organization itself are damage to reputation (83%), breach of laws and regulations (75%), service downtime (74%), customer privacy violations (71%), customer identity theft or fraud (66%) and theft of intellectual property (58%).

Comparing results from the previous survey in 2010 to these 2012 results, twice as many respondents now believe that their organization's security posture is worse than before. Hord Tipton, executive director of (ISC)2, said that decline stems in part from the increased complexity involved in securing cloud computing, managing bring-your-own device (BYOD) efforts and combating more advanced and automated attack tools. "We don't really hire additional people every year to do those things, so the workload stacks up for those folks, and when something breaks or gets out of control with your network, generally they're the ones who have to start answering questions first," said Tipton, speaking by phone.

Despite the increase in complexity, 28% of respondents did report "that they could remediate the damage from a targeted attack" within a day, according to the study. With such recently hacked businesses as Apple, Facebook, Microsoft and Twitter saying that they're still in the process of working with law enforcement agencies and investigating breaches, isn't that finding optimistic?

"It's a matter of containment: how quickly can you contain a particular breach or outbreak?" said Bruce Murphy, a principal at Deloitte & Touche who's on the (ISC)2 board of directors, speaking by phone.

"It comes down to how you define getting back to business. It can be something as serious as ... DDoS attacks on banks," said Tipton, who was formerly the CIO for the Department of the Interior. "To me, it's a matter of what you expose, to what degree you expose it, and did they get your good stuff or just make life inconvenient for you by messing up your website?"

What role does certification play in information security workers' ability to meet job requirements? That question is especially relevant for (ISC)2 members because the organization maintains multiple certifications, including the Certified Information Systems Security Professional (CISSP). According to the study, 46% of the survey respondents -- including 50% who are (ISC)2 members and 39% who are non-members -- reported that their organization requires certifications, most often (in 70% of cases) to demonstrate competency. Interestingly, 84% of government agencies and defense contractors require certifications, distantly followed by IT organizations (47%).

Bearing in mind that the study was partially funded by (ISC)2, respondents said that the certifications and affiliations that are of greatest importance to their career involve (ISC)2 (66%), the SANS Institute (32%), ISACA (31%), OWASP (18%), IEEE (16%) and the Cloud Security Alliance (13%).

Attend Interop Las Vegas, May 6-10, and attend the most thorough training on Apple Deployment at the NEW Mac & iOS IT Conference. Use Priority Code DIPR02 by March 2 to save up to $500 off the price of Conference Passes. Join us in Las Vegas for access to 125+ workshops and conference classes, 350+ exhibiting companies, and the latest technology. Register for Interop today!



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.