Google
Yesterday, an article on CBS Money Watch caught my eye: Businesses deluded about threat of cyber attack. The article was a short introduction to a recent survey conducted by Deloitte. And isn’t it spooky that the same old things keep cropping up everywhere?...
Unsurprisingly, the Deloitte report highlights that 88% of the businesses surveyed believe that they are not really at risk. As you would expect, they also identify lack of employee awareness and third party risks as top security vulnerabilities (46% of organisations don’t evaluate the security and privacy practices of vendors before sharing sensitive or confidential information, according to a recent Experian/Ponemon survey. If you’re not already fed up with trend predictions, see earlier blog post for my 2013 predictions.
But for me, these were not the most interesting points of the study...
A blog about information security, payments, risk, fraud, digital innovation and social media... Connect on LinkedIn?
Showing posts with label metrics. Show all posts
Showing posts with label metrics. Show all posts
27 February 2013
28 January 2013
GAZING AT 2013: THE RIGHT FOCUS AND THE RIGHT LANGUAGE...
Google
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...
Labels:
CISO,
compliance,
Data Breach,
Data Privacy,
data protection,
data security,
DBIR,
EU Data Protection,
Fraud,
GRC,
ICO,
information security,
metrics,
predictions,
risk management,
Social Media,
third party
1 April 2012
FROM FRAUD TO INFOSEC and vice versa... Part 1
Google
In my last post, I attempted to give some real business metrics to help secure information security investment. One of those metrics set related to our ability to link infosec to fraud and in this post I’d like to examine the connection a bit further. Lucky for me, the UK National Fraud Authority have just released their 2012 Annual Fraud Indicator (readers beware, it’s 58 pages...), so with my infosec lens, I’ll take you through the report and hopefully give you some more KPIs to think about...
18 March 2012
THE INFOSEC INVESTMENT EQUATION: CAN YOU SOLVE IT?...
Google
I can’t believe my last
post was on 4th March! I am positively thrilled that my most
popular entry so far is the one about incident
response... This means that we must be coming to terms with the fact that
data breaches are a statistical certainty and how we handle them is what
matters. Good news: this means we’ve got the attention we need. Now we need to
convert this attention into the investment it requires. External statistics may
give you the hook but, as abundant as they are, do not however make it relevant
to your business when trying to secure the infosec investment you require...
Subscribe to:
Posts (Atom)