Risk
12/5/2012
06:35 PM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Over Half Of Chief Information Officers Fail To Test Cloud Vendors' Security Systems And Procedures

Cybersecurity tops CIOs' concerns

LONDON, 5 December, 2012 – Cybersecurity tops CIO's concerns, with 84% of CIOs stating that they are either concerned or very concerned about the risks associated with IT security breaches. Yet while security issues remain the biggest concern that CIOs have about migrating their technology functions to the cloud, less than half (45%) test cloud vendors' security systems and procedures.

The news follows a report by the Cloud Industry Forum (CIF), which found that the rate of adoption by UK organisations is accelerating. Its study of 250 IT directors in private and public sector organisations found that 61% of companies are using a cloud-based service, compared with just 48% in 2011.

Other measures adopted by CIOs to tackle the cybersecurity risk include improving physical security (44%), developing business continuity processes (39%), identifying management systems (34%) and relying on an external audit provider (13%). Surprisingly, more than one-in-10 (11%) of CIOs said that they not taking any proactive action to address cybersecurity, while 12% said that they were 'not concerned' about cybersecurity.

100 UK CIOs were asked: 'How concerned are you about cybersecurity?' Their responses:

Very concerned

30%

Somewhat concerned

54%

Not concerned at all

12%

Don't know

4%

The research follows earlier findings from Robert Half that almost a quarter (23%) of Chief Information Officers (CIOs) and IT directors across the UK say they have no plans to migrate IT systems to the cloud, despite clear benefits such as cost savings and flexibility of service. As well as security concerns, CIOs say that continuity of service is a barrier to adopting cloud (36%), followed by data integrity (32%), speed of service (31%) and costs (30%).

Phil Sheridan, Managing Director, Robert Half Technology said: "Looking towards 2013, CIOs are charged with juggling multiple priorities, with regulation, integration and migration projects putting additional pressure on busy IT departments. But the risks of not migrating to the cloud, notably the achievement of significant cost reductions, may outweigh the potential security risks that concern IT executives. Budgets continue to be stretched and any potential cost savings that IT can deliver will be welcomed throughout the business.

"We anticipate significant demand for both permanent and contract technology professionals with IT security, infrastructure project management and data migration skills in 2013. While cloud migration may provide cost savings in data storage and warehousing, companies still need the requisite talent to implement and manage cloud initiatives, ensuring that IT security remains a priority."

Ryan Rubin, UK Director of risk consultancy Protiviti, a wholly-owned subsidiary of Robert Half, said: "These statistics indicate that either there is an inherent trust in cloud service providers; that they have good security governance in place or there is a lack of visibility of potential risks associated with using them. However, there is also a potential risk that CIOs are not always involved in the overall business making decision to procure cloud services – limiting their ability to carry out effective due diligence before these services are adopted.

"Since an increasingly higher percentage of IT security breaches involve third parties, gaining assurance from cloud providers is critical to managing information security risk. Whilst companies may migrate IT towards cloud providers in an attempt to reduce costs, they cannot outsource their information security risks. Unless adequately managed, the cost of security breaches - either regulatory and or legal - may outweigh the perceived benefits of moving into the cloud."

-Ends-

About Robert Half

Robert Half is the world's first and largest specialised recruitment consultancy and member of the S&P 500. Founded in 1948, the company has over 350 offices worldwide and more than 20 in the United Kingdom providing temporary, interim and permanent recruitment solutions for accounting and finance, financial services, technology, human resources, marketing and administrative professionals. Named one of the Sunday Times' 100 Best Companies to Work For, Robert Half offers workplace and job seeker resources at roberthalf.co.uk and twitter.com/roberthalfuk.

About Protiviti –

Protiviti (http://www.protiviti.com/) is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit. Through its network of more than 70 offices in over 20 countries, Protiviti has served more than 35% of FORTUNE® 1000 and Global 500 companies. The firm also works with smaller, growing companies, including those looking to go public, as well as with government agencies.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web