IT Security

Data security survey

by Mark Rowe

Though the C-suite recognises the benefits of data security, even with tools in place to address data security needs, business and IT decision makers report gaps. That is according to the first Dell Data Security Survey. It found that security concerns are limiting the adoption of cloud and mobile working.

While the C-suite is more invested in data security than in the past, IT feels executives are still not allocating the energy or resources needed to properly address data security challenges. Nearly three in four decision makers agree that data security is a priority for their organisation’s C-suite; however, one in four decision makers don’t find their C-suite to be adequately informed about data security issues.

Three in four decision makers say their C-suite plans to increase current security measures, and more than half expect to spend more money on data security in the next five years. Cost is a concern, with 53 percent of respondents citing cost constraints for why they don’t anticipate adding security features. Only one in four decision makers are very confident in their C-suite’s ability to budget enough for data security solutions over the next five years.

Steve Lalla, VP of Commercial Client Software & Solutions for Dell, said: “These findings suggest that the C-level has to be more engaged when it comes to integrating data security strategies into their business. Business leaders understand the need to invest in their security infrastructure, but that isn’t translating into updating or expanding their current systems to adequately prevent modern attacks.”

Despite increased buy-in from the C-suite, IT departments still need more business support to fully integrate data security. The report found that a lack of investment in streamlined technologies and a shortage of talent are both barriers to fine-tuning data security. A majority of decision makers (58 percent) believe that their organisation is adversely affected by the shortage of trained security professionals in the industry. A majority, 69 percent of decision makers still view data security as a burden on their time and budget. Still, nearly half (49 percent) of respondents believe they need to spend more time securing their data in the next five years than they are. Most, 76 percent believe their solutions would be less burdensome if provided through a single vendor.

Lalla said: “These findings show that the costs and time constraints that commonly accompany traditional single point solutions have an adverse impact on IT departments. For companies with hundreds or thousands of employees, managing each endpoint separately using multiple consoles is extremely inefficient and leads to a high probability of conflict or incompatibility. Implementing a single, integrated suite for IT management can drastically improve this process.”

The report showed that respondents remain highly concerned about malware, despite the fact that most have anti-malware software in place. Nearly three in four (73 percent) decision makers are somewhat to very concerned about malware and advanced persistent threats. Concern over malware threats is highest in the United States (31 percent very concerned), France (31 percent very concerned) and especially India (56 percent very concerned) – while it’s a lesser concern in Germany (11 percent very concerned) and Japan (12 percent very concerned). Only one in five respondents are very confident in their ability to protect against sophisticated malware attacks. Respondents are more worried about spear phishing attacks (73 percent are concerned) than any other breach method.

Brett Hansen, Executive Director, Data Security Solutions, Dell, said: “The fact that IT and business decision makers are not confident in their anti-malware defense implies that they may be using outdated or ineffective tools. When IT teams do not have the resources they need to proactively prevent threats and stay on top of the evolving threat landscape, they are forced to play defense using threat detection and remediation alone.”

Offices becoming more mobile?

A majority of mid-market companies (65 percent) are holding back plans to make their workforce more mobile for security reasons with 67 percent hesitant to introduce bring-your-own-device (BYOD). While 82 percent of decision makers have attempted to limit data access points to enhance security, 72 percent of decision makers believe that knowing where data is accessed will make their data protection measures more effective. Many, 69 percent of respondents say they are still willing to sacrifice individual devices to protect their company against a data breach, yet 57 percent of respondents are still concerned about the quality of encryption used by their company.

Hansen said: “Mobility and security can easily co-exist with modern data security technology that uses intelligent encryption to protect data whether it’s at rest, in motion or in use.”

With more employees using public cloud services like Box and Google Drive in the workplace, decision makers are not confident in their ability to control risks posed by these applications. Nearly four in five respondents are concerned with uploading critical data to the cloud, and 58 percent are actually more concerned than they were a year ago. About a third, 38 percent of decision makers have restricted access to public cloud sites within their organisation due to security concerns. More than half, 57 percent of decision makers who are current cloud users, and 45 percent of those planning to use public cloud platforms, will rely heavily on cloud vendors to provide security. Only one in three organisations cite improving secure access to public cloud environments as a key focus for their security infrastructure, yet 83 percent say that employees are either using, or will soon be using, public cloud environments to share and store valuable data.

Hansen said: “Security programmes must enable employees to be both secure and productive, and this means enabling technology that helps them do their jobs. Companies can try to limit or prohibit public cloud use, but it’s more effective to use intelligent data encryption to protect corporate data wherever it may go, and reduce the risk of employees working around restrictive policies in order to be productive.”

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing