Midmarket Security: 5 Risks, 5 Practical Responses
Smaller companies deal with enterprise-grade threats and compliance challenges, and partners are imposing requirements for sophisticated controls and audits that may be overwhelming. Here's how to cope.
(Registration required.)
We analyzed 699 responses to our InformationWeek Analytics 2011 Strategic Security Survey from IT and security pros at companies with fewer than 1,000 employees, and we found that they take information security every bit as seriously as large enterprises. They're wrestling with the same challenges, including managing the complexity of security, enforcing policies, preventing data breaches, and assessing risk, but they're doing it with less funding, expertise, and technology.
More Security Insights
Webcasts
- Securing the Cloud: Extend the Benefits of Traditional IT Environments to Cloud
- Perform Better in a Hybrid Cloud World
White Papers
- 2012 Endpoint Security: Best Practices Survey
- Forrester Report: Killing Data for Security and Risk Professionals
Reports
More >>"Somewhere between 30 and 150 people, you reach the really scary spot," says Lee Sharp, network and systems manager for recycling company TerraCycle. "Midsize companies have all the complexity of big companies but can't afford the big tools and can't easily enforce policy."
Problem 1: Managing Security Complexity
Managing the complexity of security is far and away the greatest challenge midsize IT organizations face--50% of our 699 survey respondents identified it as problem No. 1, 16 percentage points ahead of the next biggest issue, enforcing security policies. A smaller number of people and nodes to protect is little comfort when criminals have diversified their attacks and you're faced with increasingly mobile employees accessing business networks from insecure wireless hotspots, often using unmanaged devices.
Oh, and most midsize companies must comply with at least one, and frequently multiple, regulations, including PCI DSS, HIPAA, state privacy laws, and the Sarbanes-Oxley Act for public companies. Audits are a major time suck.
The complexity problem is exacerbated by stringent requirements from partners--often much larger companies, with more resources--whose information they handle. Small companies are being forced to sign on to stronger policies, processes, and controls and adopt expensive, sophisticated security technologies as a condition of doing business with those larger partners.
Download the April, 2011 InformationWeek SMB Digital Supplement
Become an InformationWeek Analytics subscriber and get our full "SMBs In The Crosshairs" report.This report includes 15 pages of action-oriented analysis. What you'll find:
- The 3 most common SMB vulnerabilities
- The 5 top attack vectors, and how to defend yourself
- 8 ways to make your company a difficult target
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Cyber Security Risk: A Conversation with Richard Clarke about Threats to Enterprise Software
- Cloud, Appliance or Software: How to Decide Which Backup Solution is Best for Your Small or Mid-Size Organization
- Protecting Your Brand against Malware Threats with Code Signing
- Virtualization and Your Production Environment
- Everything You Need to Know About Cloud Security but Were Afraid to Ask
Featured Resource
Download this paper to learn how Dell computers running Microsoft Windows 7 can help you make your operations more secure and meet compliance requirements.
Learn More












