Security czar: Button up or get hacked

By Robert Lemos, CNET News.com
Wednesday, February 20, 2002 10:35 AM
SAN JOSE, Calif.--The United States' top adviser on cybersecurity on Tuesday took companies to task, pointing out that many spend less on computer security than they do on coffee for employees.

Richard Clarke, the special adviser to the president on cybersecurity, told security experts at the RSA Conference 2002 here that such complacency leaves the Internet--and many other critical infrastructures--in danger of attack. Clarke cited statistics that indicate that less than 0.0025 percent of corporate revenue on average is spent on information-technology security.

"If you spend more on coffee than on IT security, then you will be hacked," Clarke said during his keynote address. "What's more, you deserve to be hacked."

Software companies have said that during tough times, businesses aren't interested in spending big for security. But Clarke said his own research has found the opposite. He further stressed that the industry needs to work together to secure the Internet as a whole, and that companies should not just worry about their own little piece of the network.

"Let's admit that the emperor's new clothes are rather skimpy sometimes," he said.

Since the Sept. 11 terrorist attacks, national interest in security has grown considerably. Clarke said the attacks showed that the United States' enemies are technologically savvy--and persistent.

"Our future enemies will understand our technology at least as well as we do," Clarke said. To combat this, President Bush in his proposed budget has pushed to increase spending on information security 64 percent, to US$4 billion, Clarke said. The increase would represent 8.1 percent of the total budget for information technology, he added.

Clarke also praised efforts by companies such as Cisco Systems and Microsoft to pay better attention to security issues. In January, Microsoft Chairman Bill Gates sent a memo to employees urging them to pay renewed attention to security issues in products.

The crowd gathered in the conference hall laughed after mention of Microsoft's security push, a strategy that has been frequently criticized in the press. Yet Clarke said the program was no laughing matter.

"Let's not just laugh and be cynical about that promise," he said. "Let's instead say to Bill Gates, 'You are right, and we are going to hold you to it.'"

The RSA Conference is the largest computer security and encryption conference in the world.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web