IBM's integrated security framework

August 2012 Information Security

To address the increasing need for an integrated security offering to deal with the growing security threats businesses face, IBM launched IBM Security Systems (ISS) late last year following its purchase of Q1 Labs. Joe Ruthven, business unit executive, IBM Security Systems, IBM Middle East and Africa, spoke to Hi-Tech Security Solutions about the new division.

Joe Ruthven
Joe Ruthven

Ruthven says the company had security products in its software portfolio before the Q1 acquisition, but not an integrated Security Information and Event Management (SIEM) system that could consolidate security threats in real-time. Now there is a single brand with a single team behind the security drive.

There are for key trends in the market driving the need for an integrated security offering in business, according to Ruthven. These are:

* The explosion of data in all areas of business, much of it not being secured appropriately.

* Nobody can deny the growth of mobile computing and this is creating a serious security vulnerability. Users are far too trusting when it comes to downloading apps and business must take the appropriate measures to protect itself.

* Cloud computing is also creating a headache for businesses and consumers as they adopt strategies that could see their data held by third parties in a variety of locations.

* Attacks on business IT are also increasing, not only in frequency, but also in sophistication. It’s no longer malware or kids having fun, but organised crime is profiting from hacking attacks, making hacking in its various forms the third most lucrative crime in the world.

These trends, among others have made security a pressing concern for business, a concern ISS is addressing through its unified offering. Ruthven says there are four dimensions to ISS’s service.

* People: Companies need to ensure the right people have access to the right privileges and access to do their jobs efficiently, but they also need to ensure that the wrong people don’t have access to information they don’t need, or may want to access for nefarious purposes.

* Data: Securing data is somewhat lower on organisations’ priorities, but with mobile and cloud services becoming more popular, as well as the rise of ‘big data’ along with governance requirements, managing your data is becoming more important than ever.

* Infrastructure: Business is good at securing its infrastructure, but securing the perimeter is no longer enough to protect from attacks.

* Applications: Applications are also under pressure, not from an access perspective, but also regarding how they behave. Again, this is especially relevant in the mobile space.

To support its security service, IBM also has its X-Force research team that monitors the security market. Its IBM X-Force Trend and Risk Report is produced twice per year and provides statistical information about all aspects of threats that affect Internet security, including software vulnerabilities and public exploitation, malware, spam, phishing, Web-based threats, and general cyber criminal activity.



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...
Industrial sector is a primary cyber target
Information Security
Threats in industrial environments are distributed with striking uniformity: APT-driven incidents constitute 17,8%, malware 14,9% and social engineering 13,9%. This pattern suggests that industrial organisations attract a broad range of adversaries with different capabilities and objectives.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Claude Mythos wake-up call
Technews Publishing AI & Data Analytics Information Security
AI has crossed a critical cybersecurity threshold and frontier models are accelerating attack lifecycles and will enable attackers to identify and exploit vulnerabilities at scale and speed, through novel methods that were previously the domain of advanced nation-state entities.

Read more...
If you cannot prove identity, you cannot claim security
Access Control & Identity Management Information Security
Cybersecurity planning for 2026 is a structural change in how attacks are executed and how trust is exploited, demanding that companies stop layering tools on top of infrastructure and instead prioritise intelligence and identity.

Read more...
95% do not have full trust in cybersecurity vendors
Information Security Security Services & Risk Management
Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels. Lack of verifiable transparency undermines cybersecurity decision-making, according to Sophos-backed research.

Read more...
From the editor's desk: When the rules change
Technews Publishing News & Events
         Welcome to the SMART Surveillance & AI Handbook 2026. We were a bit nervous about including AI in the title, since it either has a good or bad reputation depending on the individual – very few people ...

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.