Strategy should include a security assessment

July 2003 News & Events

Many businesses respond to increased information security threats by shoring up their perimeter defences. Implementing tools that serve a very specific purpose is part of the solution, but smart organisations are waking up to the need to implement a strategy that also includes security assessment.

In fact, says Anthony Southgate, general manager: Security Solutions at Dimension Data, one of the biggest issues surrounding information security investment is the fact that many senior managers simply do not recognise or understand the threat to their business. It is difficult to quantify the actual threat or calculate the ROI of any project.

"Before approving any budget plans, management therefore needs to understand the real impact of a breach on their security systems. It is also critical to be able to discern the fact from the fiction in terms of security mythology," he adds. According to Southgate, companies need to establish what degree of risk is acceptable.

55% of organisations surveyed already use security assessments as part of their ongoing strategy; 60% of the remainder intend to do so in the near future.

However, the costs of a security breach cannot always be easily quantified. Damage to reputation and brand can often be as detrimental as the physical harm done to an organisation's systems. It is vital that CEOs and senior management understand just what it means for their organisation if breaches occur. It is therefore important that organisations use regular benchmarks to help them understand their risk exposure and how this compares to their competitors.

A recently commissioned Di-Data survey revealed that while many were still focusing on products to provide protection, a significant number of organisations indicated that they wanted to move toward investing in security consultation and managed security. Of those organisations that confirmed further investment, 89% intend to allocate budget to security consultation and 62% to a managed security strategy.

"This clearly indicates a move away from creating a defence against every eventuality, toward adopting a more pro-active strategy on what to do should an attack occur," says Southgate.

"By focusing less on eliminating all risks, and more on developing a strategy for how to deal with attack, organisations will be able to benefit from a pragmatic approach to security that does not negatively impact their ability to innovate."

For more information contact Bronwyn Goeller, Dimension Data, 011 575 0000.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Pentagon appointed as Milestone distributor
Elvey Security Technologies News & Events Surveillance
Milestone Systems appointed Pentagon Distribution (an Elvey Group company within the Hudaco Group of Companies) as a distributor. XProtect’s open architecture means no lock-in and the ability to customise the connected video solution that will accomplish the job.

Read more...
Gallagher Security’s Integrate Roadshow
Gallagher News & Events
Gallagher Security recently teamed up with nine technology partners to showcase the latest integrated security capabilities at the Integrate Roadshow in Durban, bringing together about 60 attendees, including end users, channel partners, consultants, and other industry professionals.

Read more...
Ransomware impersonates employees and self-spreads
News & Events
Following a recent incident, the Kaspersky Global Emergency Response team is shedding light on an attack where adversaries crafted their own variant of encryption malware equipped with self-propagation capabilities.

Read more...
Level of RDP abuse unprecedented
Sophos News & Events
Cybercriminals abused Remote Desktop Protocol (RDP) in 90% of attacks handled by Sophos Incident Response in 2023, Sophos’ newest Active Adversary Report finds. External remote services were the number-one way attackers’ initially breached networks.

Read more...
Hexagon rebrands Qognify
News & Events
Hexagon’s Safety, Infrastructure & Geospatial division announced that Qognify has officially adopted the Hexagon corporate identity and fully integrated into the division as the physical security business unit.

Read more...
Five efficiency strategies for your security installation business
Securex South Africa News & Events
A recent conversation with one Securex South Africa 2024 exhibitor, led to the event organisers being able to share some advice on helping security installers make their businesses more efficient.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
Sales basics for security installers
News & Events
Being the best security business in South Africa means little if no one uses your services. Your business success is only partly linked to how good you are at security installations.

Read more...
From security technician to salesperson
News & Events
Being great at security sales starts with having the right mindset. How you think informs what you say and how you act; and how you act informs the results you will achieve in your business.

Read more...
From the Editor's Desk: Something old and something new
Technews Publishing News & Events
      Welcome to the 2024 edition of SMART Security Solutions’ Mining Handbook. Mining is a challenging industry for security professionals, although security is a challenge on this continent, no matter your ...

Read more...