Microsoft U.K. security chief attacks government

By Andrew Donoghue, ZDNet UK
Thursday, February 02, 2006 11:43 AM

Microsoft U.K.'s chief security advisor Ed Gibson has attacked the government over what he claims is a lack of effective reporting channels for Internet-related crime.

Speaking at the launch of a CBI report into online security for small and medium-sized businesses, Gibson said that while creating documents was all well and good, very few companies had any real notion of who they should report an electronic attack to.

"I bet if I asked anyone in this room, 'Who would you report an electronic crime to in the Police?', no one would know," Gibson said. "We are ignorant of the size of the problem. There is a real lack of meaningful statistics."

Rejecting the offer of a microphone and choosing instead to stride up and down between the panel of experts and the audience of IT and business professionals, Gibson claimed that the government was not doing enough to facilitate the timely reporting of cyber crime.

Gibson said that the decision to roll the National Hi-Tech Crime (NHTCU) Unit into a new larger agency, The Serious Organised Crime Agency (SOCA), in April 2006 would actually make it harder for businesses to work out to whom they should report an electronic crime. Gibson also attacked the amount of funding the NHTCU has received since its creation in 2001, claiming it has declined annually.

Surprising many audience members, Gibson added that the most effective way to improve online security was by individuals taking small steps such as locking down their desktop. Microsoft has been heavily criticised in the past for the poor levels of security in its products, particularly its Windows operating system.

Gibson aimed the majority of his comments at Alun Michael, minister for Industry and Regulation at the DTI, who was present at the event to launch the CBI report.

Michael responded to Gibson's charge by claiming that he had recently reported a potential attack on his own computer to the help desk at the House of Commons, which passed his report directly to the police.

Another charge made by the Microsoft security chief, who joined Microsoft in July 2005 from the FBI, where he held senior positions as a special agent for 20 years, is that there need to be stronger punishments in place for those who commit electronic crime.

"We can talk and talk about what is in the book [CBI report], but legislation alone will not do it. We can talk about the Computer Misuse Act till the cows come home but unless there are any meaningful punishments for computer crime then none of this makes sense," claimed Gibson.

Earlier this week, the government said it would update the Computer Misuse Act. This will include a maximum 10-year prison sentence for individuals who maliciously impair the operation of a computer, or hinder or prevent access to programs or data.

The CBI report, called Securing Business Value Online, is specifically aimed at small to medium-sized companies which Michael identified as "the weakest link in the chain" when it comes to electronic security. "The old adage that the chain is only as strong as its weakest link, is relevant here," Michael said.

Michael added that effective online security stemmed from taking the right approach to the problem rather simply buying in a fix-all technology. "The problem is at heart how companies are managed and not about waiting for some technological silver bullet."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Release management: Unnecessary evil or Holy Grail?

Tech Management

Though organizations may dread these words, release management is an integral step throughout the software development process. Erica Henson explains more.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web