The CIO's guide to managing change in Asia

Asia worried about insider threat

By Lynn Tan, ZDNet Asia
Thursday, October 30, 2008 05:15 PM

Security continues to be a major concern in ZDNet Asia's latest survey on the region's top IT priorities, with internal risks being the most important among them.

According to the study, which polled 722 respondents across the Asia-Pacific region in August, 4.7 percent of respondents said security was currently a priority.

When asked what their top three security priorities were, 52.8 percent said they regarded protecting the network from insider threat as the No. 1 priority. Other concerns included securing network access from outside the LAN (49.7 percent) and secure employee communications (44.2 percent).


Source: ZDNet Asia IT Priorities Survey 2008/09

Across the Asia-Pacific region, security issues were strongest in Singapore (13.6 percent) and Greater China (12.2 percent).

By company size, security issues were about as important across all sizes of organizations. More respondents in midsize businesses (10.3 percent) regarded security as a priority, compared to small (8.0 percent) and large (8.9 percent) businesses.

Michael Warrilow, director of analyst company Hydrasight, said: "Protecting against insider threats is the most difficult security challenge."

"Over much of the last decade, security strategy has primarily been a matter of 'keeping the bad guys out'...security strategy must evolve to realize that bad--and good--guys might be anywhere," he added.

"This requires a much more sophisticated security strategy, not simply access control rules, such as 'deny' and 'allow'," Warrilow said.

Elaine Lee, IDC Asia-Pacific's market analyst for hardware and software, noted that as the insider threat grows, "organizations now have to look into their employees' behavior".

"Employee, the trusted entity, can be a very dangerous insider threat with the availability of his power, trust and knowledge in the organization," Lee said. "As such, management must pay close attention to many aspects of an organization, including its business policies and procedures, organizational culture and technical environment."

Protecting against internal risks
Eric Hoh, vice president of Asia South region at Symantec, added that to guard against insider threats, enterprises require more than network security. "They must protect their sensitive information itself," he advised.

Enterprises can turn to data loss prevention (DLP) to address this issue, Hoh said. He highlighted three key steps to get started on DLP:

1. Discover and protect confidential data
"Enterprises first need to accurately discover confidential data wherever it is stored, used, copied or sent. Once this data is identified, enterprises can then take proactive steps to protect confidential information before it has a chance to be transmitted," Hoh explained.

2. Monitor all data usage and prevent confidential data exiting
"Preventing confidential data from being transmitted outside the enterprise first requires comprehensive monitoring of multiple exits and endpoints," he said, adding that e-mail is "only part of the problem". Web applications such as instant messaging and blogs, as well as other electronic channels, may also be points of weakness, he noted.

"Storage devices such as USB devices, CD/DVDs and [Apple] iPods also provide easily accessible endpoints to which confidential data can be copied. It's not enough simply to monitor security violations; the key is to prevent sensitive data from being transmitted by blocking it, in effect closing the door before the proverbial horse is out of the barn," Hoh said.

3. Change employee behavior via awareness and education
"The effectiveness of even the best technology and processes can be undermined if employees do not understand the value of their company's information assets and their role in mitigating risk," he said. "With heightened awareness, however, employees can also become a company's strongest line of defense and its most valuable security asset."

According to the Symantec executive, while formal security awareness training programs and clear security policies will be useful, the "most effective education comes through intervention at the time of action".

"Many data breaches are the result of simple user error. People make mistakes. They forget. They misunderstand. But they can also correct themselves--if they know they erred," Hoh said.

According to IDC's Lee, other security challenges that Asian companies face include "localized language malware, which international vendors might be slow in releasing patches or miss completely".

Another security concern is the issue of criminal activities in emerging countries such as "China and India where IT adoption is in [the] infant stage and outsourcing is booming", she said. China, with less established security infrastructure and policies, is "one of the top countries for hosting phishing Web sites."

Lynn Tan is a freelance IT writer based in Hong Kong.



Download full report on ZDNet Asia IT Priorities Survey 2008/09
Includes commentary and analysis from independent IT consultant Graeme Philipson


WORTHWHILE?

0

0 votes
Save to my library  Save to My Library  
Blog

Talkback 0 comments

There are currently no comments for this post.


Implementation of IT a top concern
Technology is important, but how it is implemented in a business environment is the paramount concern of region's CIOs, ZDNet Asia survey finds.


CIOs have business on their minds
Tech leaders in Asia identify business management as key priority, ZDNet Asia survey finds. Analysts say credit crisis further drives transformation of CIO role.


Asia worried about insider threat
Managing data leaks from within the organization is the top security priority of businesses in the Asia-Pacific region, according to a new ZDNet Asia survey.


Crisis bodes well for utility computing
As companies reconsider their tech needs, vendors plan to roll out products that will help enterprises generate more returns on their investments.


Web development gaining importance
Such software and services enter the realm of top 10 priorities of CIOs in Asia, ZDNet Asia survey finds.


Open source gains favor in Asia
Over 76 percent of companies in ZDNet Asia survey deploy open source apps. But analyst says most businesses still don't have policies governing such adoption.


Green IT sprouts slowly in Asia
Although the number of companies implementing eco-friendly practices has grown, environmental issues still rank low on Asia's business agenda.


Web 2.0 brings business opportunities
Increasingly, companies in Asia are seeing benefits of adopting blogs, social networks and Wikis.


Different country, different priorities
Management is top IT priority for India but not for China, where businesses are concerned more about software issues.


CIO Insights

Mobile shows the way for Golden Village
Singapore's largest cinema operator spends time gathering consumer data to identify new ways to deliver its services, notes CIO Roger Lim.

YCH Group looks to Web 2.0
Logistics company is monitoring potential role of Web 2.0 in improving user experience and communication, says CIO James Loo.

DHL Express aims to deliver on flexibility
Providing customers more flexibility and variety will prove critical in current market conditions, CIO Nariman Karimi says.