Grey WLANs and web services are top risks
Published: 26 May 2002 20:52 BST
The fact that security now has to be embedded in everything means that security companies have to deliver more than ever on making their products work together. Although it is under the control of one company, Check Point's Opsec standard is a good one, says Goldberg. "Someone should control those APIs, otherwise you have chaos. The industry has to trust someone, and Opsec is market driven."
The trickiest thing is the people and policy issue. Education is important but the subject is complex, said several people. "We tell them computer security war stories, and users are stunned," said Churcher. But even if users understand security, it must be invisible to them, he sai: "If they can turn it off, they will."
And even when people understand, their agendas may differ. "Sometimes IT puts in solutions, but human resources policy doesn't marry up," said Mark Smith, a solicitor specialising in IT law at Morgan Cole. Alternatively, HR may drive through a policy of encouraging home-working, without consulting IT people, and getting it secure first.
"At some level security can prevent you or your customers from doing things," said Goldberg. But the limitations of security are perhaps to do with how much users can take. Make things too hard and users rebel. A rule of thumb suggested by one delegate is to tighten things up until a significant percentage complain, then take it back a bit.
How many hacks?
The one thing everyone agrees on is that security breaches are widespread. "about half of UK businesses have at least one security breach in a year," said John Ryan, sales director at Entropy.
Another hearsay indication is the number of people disciplined. "We deal with one case of web or email abuse per month already," said Smith. "Most are settled out of court, with a compromise agreement which prevents publicity."
It is obvious that security is never going to be "solved", but it is encouraging to see end users and suppliers agree on the issues.
Have your say instantly in the Tech Update forum.
Find out what's where in the new Tech Update with our Guided Tour.
Let the editors know what you think in the Mailroom.










