The industry reflects, looks ahead

By Staff, ZDNet Asia
Friday, March 14, 2008 06:39 PM

Ashley Wearne, McAfee's vice president for Australia, New Zealand, Southeast Asia and India

Ashley Wearne,
McAfee
As threats evolve and grow, enterprises can no longer depend on a motley collection of standalone security products, and they need an integrated security approach.

Q. Gartner issued a report warning IT heads to prepare a recession budget. What is your view?
Wearne: The business reality is CIOs and security managers have always had to compete with other corporate functions for funds. CIOs are well-schooled in doing more with less.

At McAfee, we are able to help our customers with ways to model the benefits of security technology and show their impact on risk reduction. This allows them to have a quality conversation with the business people regarding their security spend.

Name three hot technologies to watch in 2008, and explain why.
The first is data loss prevention. Enterprises are realizing that loss of data and leakage of confidential information is the most important security threat. As enterprises give employees more access to information, there are more opportunities to lose information--through USB thumb drives, e-mail, disk drives, employees who cut and paste data or post information on online forums and Web sites. While organizations want to give employees a lot of tools, they also need to identify the most important data, who has access to those data, and how to control access.

A McAfee study found that six in 10 companies suffered loss of confidential data last year, and one out of every three IT decision makers believes that a major data loss incident could be serious enough to put their company out of business. Enterprises are beginning to invest in security solutions that will help them control data loss and leakage. Analyst predictions are that every company will adopt data loss protection technology over the next three years.

The second is network intrusion prevention, integrated with network access control (NAC). As soon as a user connects to the Internet, he is exposed to threats that can come from anywhere in the world and from any source--e-mail, Web surfing, spyware. In addition, today's attacks are stealthy and complex.

The deployment of network intrusion prevention devices remains a high growth component in enterprise security strategy. IPS systems keep networks and network-connected devices safe with comprehensive threat prevention. Today's IPS technology is much advanced, with ability to monitor access policy and the users who have already connected to the network. If the network traffic from those users subsequently breaks corporate policy (for example, due to rogue programs or illegal sign-ons or virus) they can be removed from the network to a quarantine area and remediated automatically.

The third is blade appliances to handle security functions. The increasing speed of networks from 1Gb to over 10 Gb leads to massive increases in the amount of traffic to be inspected at the gateway for malicious content. Additionally the continually increasing volumes of spam and legitimate e-mail are resulting in demand for much higher throughput at the gateway. Of course, with these increases in speed and data volumes, downtime is even less acceptable, and the need for expansion an even more important criteria.

Blade appliances with extra high speed throughput will make a big entry into the security space in 2008 to handle gateway traffic inspection.

The biggest mistake I see CIOs make is...
... Undertaking new security technology projects without including integration between technologies as a criteria. As threats evolve and grow, enterprises can no longer depend on a motley collection of standalone security products, and they need an integrated security approach.

As they are likely to use products from more than one vendor, it is important to ensure the products automatically communicate with each other, and in the event of an attack on the network, the different technologies are able to put into motion a series of events to identify, contain and fix the problem.

Work-life balance is...
... A false expectation. Expectations are not realistic because of two reasons. One, people think that the balance must be there every day and, two, people think that to have balance, time spent at work and outside of work must be equal. Work needs to be a subset of our life, and since it's our life, we must take more control of it and not just hand it over to the company.

 Lenovo 

WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Release management: Unnecessary evil or Holy Grail?

Tech Management

Though organizations may dread these words, release management is an integral step throughout the software development process. Erica Henson explains more.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. acquisition
  2. acquisitions
  3. ceo
  4. china
  5. financial
  6. google inc.
  7. green it
  8. ibm corp.
  9. india
  10. industry
  11. information technology
  12. it outsourcing
  13. job
  14. microsoft corp.
  15. network
  16. outsourcing
  17. revenue
  18. singapore
  19. software
  20. u.s.