How IT Departments Can Help Rather Than Hinder Security
Chubb Corp. chairman tells IT leaders that security and business continuity planning must go beyond the walls of IT to include involvement at the executive and board levels.
In a speech last week to IT executives and corporate risk managers at the Bureau of National Affairs' (BNA) cybersecurity summit, Chubb's Dean O'Hare said IT security planning must not be confined to information technology departments. He advocates that it rise to the corporate governance level, involving oversight by top executives and boards of directors.
"It is increasingly clear that we cannot manage these risks within any one silo. Cybersecurity must be an integral part of a company's overall security planning," O'Hare said in his speech to the BNA, portions of which were released by Chubb. "Information technology experts cannot do this alone. They must work with security, human resources, risk management, general counsel and line management across the entire enterprise to develop policies and procedures to minimize risks."
O'Hare's words should be welcome words to corporate IT executives, many of whom have sought for years to attract that level of attention and input -- not to mention funding -- from CEOs and directors for their IT security and business continuity plans.
Many Companies Still Taking Security Shortcuts
Although Sept. 11 has brought a renewed focus on devising robust security plans, many companies reportedly are still lagging on that front. A recent report by Gartner Inc. found that many companies remain focused on inexpensive tactics such as updating and testing their business-continuity plans, rather than making major changes, such as moving data centers or offices to more secure locations.
O'Hare also said in his remarks that there must be across-the-board cooperation between IT and other in-house departments, as well as cooperation among companies, industries and the public and private sectors when it comes to building security strategies.
O'Hare cited what he believes to be good examples of large-scale cooperative efforts aimed at boosting cybersecurity at the industry level. They include the National Association of Manufacturers' Homeland Security Committee, which recently formed to help member companies understand key operational and policy issues such as cybersecurity, and the Critical Infrastructure Protection Board, formed by President Bush's chief cyber security adviser, Richard Clarke, to improve coordination between federal agencies and businesses.
Among his other points:
- Cooperation and trust between business and law enforcement is critical to thwarting e-security threats. He said a major problem is that too few companies report cyber crimes to the police or FBI, out of fear that negative publicity will hurt their business. O'Hare said: "When a company fails to reach out to law enforcement, it leaves itself more vulnerable to future crimes."
- Corporate execs have a strong personal interest to ensure their cyber security plans are as strong as possible: a threat of personal liability lawsuits from shareholders or businesss partners due to an IT security failure.
The Bureau of National Affairs (BNA) publishes news, analysis, and reference materials covering legal and regulatory developments for corporate and government leaders.
March 01, 2002
IT managers must think like hackers to stop them. That's the premise behind a week-long seminar coming to Boston on Monday. In its fourth year, Ernst & Young's Xtreme Hacking focuses on host and network security defense.