Company executives admit IT security gaffes

Most of the world's top executives now consider security the single most important issue for their corporate networks, according...

Most of the world's top executives now consider security the single most important issue for their corporate networks, according to a new survey. But at the same nearly four in five admit they open e-mail attachments from strangers.  

The survey from the Economist Intelligence Unit found that security was the top network-related issue for 78% of the 254 senior executives worldwide who responded to the survey. 

Respondents ironically say most of the problems were caused by employees, estimating that 83% of security problems were initiated internally, from sabotage, espionage or mistakes. Despite this, 78% of executives admitted to having clicked on an e-mail attachment from an unknown person within the last year, a figure the EIU found "astonishing". 

Such blunders have helped to drive the cost of network attacks from £1.8bn in 1997 to £6.5bn last year, according to Computer Economics figures cited by the EIU. This is driving security spending to rise faster than overall IT spending. On average the executives spent 9% of their IT budgets on network security in 2002, rising to 11% last year and expected to hit 13% this year.

Executives are aware that their networking priorities - such as giving remote workers access to the network and making customer and financial data available to employees - are inextricably linked to security problems. More than 80% of executives admitted their goals left their firms vulnerable or extremely vulnerable to threats.

Security spending is moving from perimeter protection and intrusion detection to better tools for preventing attacks and recovering when they happen, executives said. Thirty-two percent said they already used or planned to use managed security services in the next two years, with another 14% they would use them in the long term. However, most of these companies (70%) are small and medium-sized firms.

The survey found that chief executive officers are increasingly taking responsibility for network security policy, while some companies are beginning to appoint a chief security officer, a move applauded by AT&T.

"For any company, it is virtually impossible to ensure protection of assets without one person owning the focal point," said Ed Amoroso, information security officer at AT&T. 

Security moved up from its second position in last year's survey, when reliability and availability were the biggest concern. 

The online survey canvassed 254 senior executives, with 40% of respondents from Europe, 27% from North America and 21% from Asia-Pacific, mostly representing the financial services, professional services, manufacturing, transportation and energy sectors.

It was supplemented by in-depth interviews with executives and analysts. The research took place between March and April of this year.

Read more on Network software