By Jack M. Germain TechNewsWorld
10/01/07 9:23 AM PT
A recent Forrester study, which surveyed 153 IT professionals and security decision makers, found that organizations spend up to $13 billion globally for direct malware remediation costs. Based in part on that spending, 97 percent of all enterprise IT staff consider themselves prepared to deal with Web 2.0 security issues. However, 79 percent reported frequent attacks from malware.
Crystal Reports - Discover the Latest Innovations. Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.
While many sectors of the business community are accepting Web 2.0 usage with open arms, enterprise IT departments are not prepared to deal with the consequences posed by related threats, according to recent research.
IT professionals also largely lack risk awareness, user training and consistent policies related to Web 2.0 threats, according to a security report by Forrester Research commissioned by enterprise gateway security firm Secure Computing.
"The report reveals a security blind spot. Some 90 percent of enterprise organizations are still deploying security measures designed for the last generation of attacks," Ken Rutsky, executive vice president of product marketing for Secure Computing, told TechNewsWorld.
To help enterprises close this security lapse, Secure Computing launched on Monday its Secure Web 2.0 Anti-Threat Initiative (SWAT). Secure Computing designed the new security service to raise awareness of Web 2.0 threats, provide essential guidance on threat protection and deliver protections that help organizations address the increased Web 2.0 risks, Rutsky said.
As part of SWAT, Secure Computing will offer organizations research findings, best practices, design criteria, white papers and product information.
Forrester's Findings
The study, which surveyed 153 IT professionals and security decision makers, found that organizations spend up to US$13 billion globally for direct malware remediation costs. Based in part on that spending, 97 percent of all enterprise IT staff consider themselves prepared to deal with Web 2.0 security issues.
However, 79 percent reported frequent attacks from malware. Some 57 percent of those surveyed said they were concerned about viruses. Fifty-one percent said they have concerns about trojans.
Forrester concluded that a gap exists between the level of concern over Web 2.0 security issues and the actual level of preparedness displayed by organizations now using Web 2.0 applications.
Misplaced Spending?
The Forrester report suggests that enterprise spending for network security involving Web 2.0 exposure may be misdirected. While nearly 97 percent of those surveyed consider themselves prepared for Web-borne threats, 68 percent conceded that there is room for improvement.
Despite their use of traditional security measures, enterprise organizations responding to the survey said they were experiencing more than infrequent occurrences of malware. Viruses and spyware were the leading issues they reported.
Some 46 percent of these organizations reported that they spent more than $25,000 in the last fiscal year for malware cleanup exclusively, Forrester disclosed.
"We are seeing daily new Web 2.0 threats to support ID theft or malware that opens back doors to corporate networks. We see key-logging programs load up on workers' computers upon visiting Web sites," Paul Henry, vice president for technology evangelism for Secure Computing, told TechNewsWorld.
Survey Says
Enterprise users of Web 2.0 applications recognize value from some of the new Internet features, according to 96 percent of those responding. However, less than 5 percent have implemented comprehensive gateway protection, Secure Computing's Rutsky said.
Another 57 percent said that taking away access to social networking and rich media sites will visibly increase employee productivity, according to the survey results.
Some 92 percent of the respondents indicated that outbound data leakage prevention is an important aspect of Web filtering. Fifty-eight percent consider data leakage an extremely important business concern, the report noted.
However, most existing enterprises are still depending on products designed for Web 1.0 threats, noted the study. Only 33 percent of the respondents have data leakage prevention capabilities in place today.
Not Yet Ready
Malware such as the Storm Worm exploits Web 2.0 weaknesses, according to Secure Computing's Henry. Losses to businesses hit with intrusions have doubled in the last year, he said.
At least 75 percent of enterprise Web 2.0 users say they are prepared, but 80 percent of their networks are still being hit, Rutsky added.
"This is costing enterprise organizations at least $30 per user per year just for the malware clean up," said Henry.
Report Recommendations
Given the complexity of the current threat and technology environments, Forrester Research and Secure Computing recommend that organizations look beyond a simple filtering solution and employ next-generation Web filtering technologies. The goal is to put in place enterprise-grade performance, scalability and support for management.
Next generation capabilities include reputation services, blended threat protection and behavior-based detection, explained Henry. Additionally, outbound content control such as data leakage and application control is essential.
Also, IT managers have to re-examine the adequacy of security policies and protection capabilities. Report data shows that most organizations are confident that their protection policies and mechanisms are adequate in the face of the latest trends of Web-borne threats, especially those connected with Web 2.0 applications.
To reach this goal, organizations have to improve user awareness and training on Web 2.0 and Web-borne threats.
"The infrastructure is now beginning a refresh cycle for Web filtering and Web proxy. Organizations need to replace several existing products with a single one. What they are using has reached the end of its life," Rutsky said.
Has the E-Card Scam Storm Blown Over? September 21, 2007
"We're seeing the same kind of attack, but it's not always about greeting cards now," said Doug Bowers, senior director of anti-abuse engineering for Symantec. Though actual dollars lost to the summer's trend of e-card-borne malware were relatively small, the legitimate e-card industry has promised to bolster its security measures.
Related Stories
MontaVista Targets Security, Mobility With Linux Releases September 28, 2007
"This release showcases the momentum of Linux on mobile," Amanda McPherson, marketing director for the Linux Foundation, told LinuxInsider. "It also shows how Linux is available on more architectures, supporting more devices than any operating system in history. MontaVista has done a lot of good work on power management and real time capabilities that benefits the entire Linux ecosystem."
TJX Asked Too Much, Protected Too Little, Say Canadian Officials September 26, 2007
Retail conglomerate TJX, the company from which millions of peoples' credit card information was stolen several months ago, was reprimanded by Canadian officials in a report. The Office of the Privacy Commissioner said the retailer took too much information from customers and held it for too long, thus allowing more data to be compromised should the system be hacked.
More by Jack M. Germain
Yahoo Lets FOSS Community Drive Its Traffic Server November 04, 2009
Yahoo Traffic Server is an app server for builders of cloud services. The software package enables session management, authentication, configuration management, load balancing and routing for an entire cloud computing stack. Yahoo has now open sourced a version of the application through Apache.
Is AES Encryption Crackable? November 03, 2009
A team of researchers has discovered what they think could be a flaw that leaves AES encryption open to attack. The technique has only been shown in a theoretical setting; in practice, such a hack would be very difficult to pull off. Still, such a finding could bring into question the faith that's been placed in AES -- and spur new innovation to make encryption even better.
Windows 7 Is a Snooze October 29, 2009
It's accurate to say that Windows 7 straightens out some of the problems with Vista. Aside from that, though, there aren't a whole lot of standout reasons to upgrade to the new OS, especially if you're currently on XP or you honestly don't mind Vista. The new features that are present aren't quite worth the trouble to learn how to use, and if you happen to have even slightly old equipment, forget about it.