Survey: Complexity Causes Security Incidents/System Outages
AlgoSec found that more than 50 percent of respondents reported a security breach, system outage, or both, due to complex policies
Roswell, GA – October 15, 2012 – AlgoSec, the market leader for network security policy management, today announced the release of "The Dangers of Complexity in Network Security," a report based on a survey of more than 125 IT security professionals that reveals complex network security policies, such as those found in multi-vendor environments, are directly related to system outages and security breaches.
The survey found that more than 50% of respondents reported a security breach, system outage, or both, due to complex policies. The report highlights that nearly 94% of organizations have deployed multi-vendor environments and nearly 75% of organizations manually manage networksecurity, despite the popular belief from roughly half of the respondents that consolidation would simplify management.
More Security Insights
- The 12 Critical Questions You Need To Ask When Choosing an AD Bridge Solution
- A New Set of Network Security Challenges
"Information systems' complexity has grown exponentially yet we continue down the same path - adding more and more layers of complexity," said independent information security consultant Kevin Beaver of Principle Logic, LLC. "Many IT managers and administrators couldn't tell you how secure their networks arebecause they simply don't know what's where and what's currently at risk. Complexity - and failing to acknowledge the complexity - are core contributors to the network security problems we face today."
Key findings from "The Dangers of Complexity in Network Security" survey include:
? Complexity Causes Risk – A majority of respondents reported that complex policies have caused a system outage or a security breach. Because of complex policies, 27.8 percent experienced a system outage, 14.3 percent experienced a security breach and 9.8 percent experienced both a system outage and a security breach.
? Network Environments Are Overwhelmingly Multi-vendor– According to the report, 93.9 percent of respondents have deployed solutions from multiple vendors in their environment with 56.5 percent having deployed solutions from four or more different vendors.
? Multi-vendor Environments Are Complex – "The Dangers of Complexity in Network Security" reveals that the greatest challenge of working with multiple vendors is the different expertise required (48.5 percent) while the greatest challenge of working with multiple devices is too many policies to manage (42.7 percent).
? Consolidation is Key to Simplifying Management – When asked, "What is the greatest benefit of consolidating network security vendors?" 48.8 percent responded, "Simplified management." Conversely, 36.9 percent believe that consolidating vendors prevents selecting best-in-class solutions.
"Organizations that manually manage complex multi-device and multi-vendor environments are making it harder on themselves than necessary to enforce their desired security posture," said Nimmy Reichenberg, Vice President of Marketing and Business Development, AlgoSec. "The good news for information security teams is that security policy management automation enables organizations to simplify policy and consolidate the number of consoles to manage, in turn improving security operations and reducing risk - even in the most complex environments."
? Findings from "The Dangers of Network Security Complexity" survey are available for download at: http://www.algosec.com/en/resources/examining_the_dangers_of_complexity_in_network_security_environments.
? Additionally, AlgoSec and Kevin Beaver, CISSP and independent information security consultant with Principle Logic, LLC will be examining the survey findings with in an upcoming webcast on November 1 at 11am ET. Register here.
AlgoSec is the market leader in network security policy management. AlgoSec enables security and operations teams to intelligently automate the policy management of firewalls, routers, VPNs, proxies and related security devices, improving operational efficiency, ensuring compliance and reducing risk.