The Wayback Machine - https://web.archive.org/web/20120623073932/http://cloudcomputing.sys-con.com:80/node/2298671

Welcome!

Cloud Expo Authors: Cloud Ventures, David Smith, Srinivasan Sundara Rajan, App Man, Maureen O'Gara

Related Topics: Virtualization, Web 2.0, Cloud Expo, Security

Virtualization: Blog Post

The Exec-Disconnect on IT Security

Different chiefs give different security stories

A recent survey shows that there is a wide gap between CEOs and Chief Security Officers when it comes to the origin and seriousness of security threats.  They differ on how they view threats to IT Infrastructure  and remain far apart on how to best address an issue that according to analyst reports, costs organizations more than $30 billion annually.  The survey of 100 CEOs and 100 CISO (or other C-levels with security responsibility), shows that the discrepancy is often due to lack of communication.  36% of CEOs said that they never get a security report from their CISO and only 27% receive updates on a regular basis.  Is it the CISO that doesn’t report back or the CEO that is not interested?  Let’s look at some more data.

The CISO felt that the biggest threat was from internal (their employees) due to lack of education and attention while the CEO felt that the biggest threat was from the outside, such as phishing attacks.   Thus, 61% of CEOs said they did have enough time and resources to adequately train the staff on how to mitigate threats while Only 27% of CISOs felt the same.  It’s opposite day.  When asked if their IT systems were ‘definitely’ or ‘probably’ under attack without their knowledge, 58% of CISOs said yes while only 26% of CEOs agreeing.  The chasm grows.  What percentage of each, do you think, said they were very concerned about their IT systems getting hacked?  30 seconds on the clock, please.  Don’t peek.  Only 15% of CEOs and ‘only’ 62% of CISOs are anxious about breaches.  15%?  That’s it?  Maybe they have great confidence in their security team…or, they don’t have the information.  65% of CEOs admitted to not having the sufficient data needed to interpret how security threats translate to overall business risk.  Wow, the very day-to-day operations.  Granted, the CEO is further removed from the specific threats and how they are handled but there is clearly a distance between how each views threats and the company’s ability to successfully mitigate them.

Lack of interest or lack of understanding/information?  Probably both.  An old adage was that a great boss hired people who were good at the things he/she wasn’t so good at.  Surround yourself with those who know their areas better.  Or maybe there is a culture that you don’t alert the top unless it’s dire, critical or unstoppable.   Communication or interest, it is evident that the C-suite isn’t really talking about these critical business issues especially when three times as many CEOs worried about losing their jobs following an attack than did CISOs.

ps

References

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud,compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1] o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]


Read the original blog entry...

More Stories By Peter Silva

Peter Silva covers security for F5’s Technical Marketing Team. After working in Professional Theatre for 10 years, Peter decided to change careers. Starting out with a small VAR selling Netopia routers and the Instant Internet box, he soon became one of the first six Internet Specialists for AT&T managing customers on the original ATT WorldNet network.

Now having his Telco background he moved to Verio to focus on access, IP security along with web hosting. After losing a deal to Exodus Communications (now Savvis) for technical reasons, the customer still wanted Peter as their local SE contact so Exodus made him an offer he couldn’t refuse. As only the third person hired in the Midwest, he helped Exodus grow from an executive suite to two enormous datacenters in the Chicago land area working with such customers as Ticketmaster, Rolling Stone, uBid, Orbitz, Best Buy and others.

Bringing the slightly theatrical and fairly technical together, he covers training, writing, speaking, along with overall product direction and evangelism for F5’s security line. Prior to joining F5, he was the Business Development Manager with Pacific Wireless Communications. He’s also been in such plays as The Glass Menagerie, All’s Well That Ends Well, Cinderella and others. He earned his B.S. from Marquette University, and is a certified instructor in the Wisconsin System of Vocational, Technical & Adult Education.

Cloud Expo Breaking News
SYS-CON Events announced today that ServerCentral, Chicago’s leading provider of colocation, cloud, network connectivity, and managed services, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. ServerCentral provides highly reliable IT infrastructure in secure facilities across North America, Europe, and Asia. Delivering industry leading service levels on colocation, cloud, IP connectivi...
SYS-CON Events announced today that Net Optics, Inc., the industry’s leading provider of intelligent access and monitoring architecture, will exhibit at SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. Net Optics is the leading provider of Intelligent Access and Monitoring Architecture solutions that deliver real-time IT visibility, monitoring and control. As a result, businesses achieve peak performan...
SYS-CON Events announced today that 1010data, Inc., a market leader in enabling the analysis, sharing and monetizing of Big Data, has been named “Silver Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. 1010data provides a unique, cloud-based platform that unifies Big Data and analytics. It is used by hundreds of the world’s largest retail, manufacturing, telecom, and financial services ente...
10th International Cloud Expo, held on June 11–14, 2012 at the Javits Center in New York City, featured four content-packed days with a rich array of sessions about the business and technical value of cloud computing led by exceptional speakers from every sector of the cloud computing ecosystem. The Cloud Expo series is the fastest-growing Enterprise IT event in the past 10 years, devoted to every aspect of delivering massively scalable enterprise IT as a service. We invite you to enjoy our ph...
“Big Data is not simply code for lots of information,” observed Victoria Kouyoumjian, Sr. Business and Technologies Strategist at Esri, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “Instead,” Kouyoumjian noted, “Big Data refers to information in myriad different formats from varying sources – and many of these digital formats and streams haven’t existed until recently.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the stronge...
“The definition of cloud and cloud services continues to evolve,” observed Robert Crespi, VP, CIO at Cervalis, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “As such it is difficult to predict the growth,” Crespi continued, “we see more and more customers migrating to a cloud model with virtualization as it core.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the strongest benefit of cloud computing is how it enhances business ...
“Cloud computing represents a paradigm shift for IT, transforming computing power into a utility,” observed James Weir, CTO and Co-Founder of UShareSoft, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “While cloud adoption remains in the early stages,” Weir continued, “this shift means that the overall market will grow massively in the coming years.” Cloud Computing Journal: Agree or disagree? – "While the IT savings aspect is compelling, the strongest benefit of cloud co...
This year's Cloud Expo New York appeared to be double the size of last year. Not only were there more solution providers on the expo floor, there appeared to me quite a few additional sessions to attend. I felt even the session quality was better than last year, with more knowledge spread across various tracks, and it was obvious the expertise was well, more expert than before. There also appeared to be more attendees, and in greater diversity than the previous year. Of course, all of this impro...
“The productization of Big Data will be an interesting trend to track, and I think we'll start to see some significant investment in this area over the coming months,” noted Scott Sneddon, Vyatta’s Director of Cloud Solutions, in this exclusive Q&A; with Cloud Expo Conference Chair Jeremy Geelan. “We at Vyatta think this trend is exciting,” Sneddon continued, “because these kinds of new ventures will always need powerful and creative networking and security solutions.” Cloud Computing Journal: A...
SYS-CON Events announced today that Fortress ITX, a leading provider of network infrastructure services, has been named “Bronze Sponsor” of SYS-CON's 11th International Cloud Expo, which will take place on November 5–8, 2012, at the Santa Clara Convention Center in Santa Clara, CA. FortressITX is a Cloud Integrator serving the NY Metro area providing complete IT integration and unparalleled Hosted Exchange, Hosted PBX, Connectivity and Virtual Desktop Integration (VDI) services. FortressITX als...