• Home
  • About
  • Contact Me

IT Managers Inbox

Resources for IT Managers

  • All Topics
    • Productivity Tips
    • IT Security
    • IT Operations
    • Help Desk
    • Management
    • Leadership
    • Project Management
    • IT Service Management
    • Career and Training
    • Featured Posts
  • Management
  • Leadership
  • Project Management
  • IT Service Management
  • Career and Training

What the Economic Crisis Means for IT Security and Risk Management

By Sam Grier

PC and lockEMA has issued a new advisory that highlights emerging threats in IT Security and Risk Management due to the financial crisis. Including the anticipation of new compliance issues (W3D), “What Washington Will Do”. SOX emerged from a downturn.

Enterprise Management Associates (EMA), a leading IT management research and consulting firm has released a new advisory note titled, “What the Economic Crisis Means for IT Security and Risk Management.” In the advisory note, EMA research director, Scott Crawford, highlights the impact of the current financial industry meltdown, and its implications for the management of security and risk in IT.

“Clearly, the fallout from this crisis poses serious issues for IT security and risk management. Professionals in these fields should be thinking seriously about what they may be facing as a result – but that’s not all,” said Crawford. “They also must understand how this crisis came about in order to be prepared for what will follow – as well as what it says about the mindset of the business when it comes to managing risk in any respect.”

Crawford focused on the increased IT security threats and risk management issues that come into play when the financial industry is unstable. Some examples of the economy’s impact on IT security, risk management and compliance include:

  • Opportunistic attackers will take advantage of many aspects of the crisis. Examples range from phishing attacks that target desperate individuals seeking debt relief, to more retaliatory attacks launched in frustration and resentment against financial businesses themselves. Some, however, may use the appearance of a retaliatory attack simply to hide what is actually espionage, infiltration, or attempted data theft.
  • Widespread weakness among targets will increase opportunistic risk. Just as significant is the risk posed by the new weakness of financial institutions – and possibly some governments stretched to cover losses in the private sector – both of which are among the most common targets of attack.
  • Increased M&A activity will complicate security and risk management. As former financial services competitors take over one another in a wave of mergers and acquisitions, IT as well as security teams on both sides of a deal will find it a challenge to safely integrate a formerly foreign environment.  M&A activity may further open the door to opportunistic phishers who recognize that customers may not know who owns their bank from one day to the next.
  • Businesses should look to the security and risk management values of every management tool and technique in the enterprise. The need for visibility throughout the network highlights the value and importance of tools not only in security, but in network, systems and application management as well. IT management tools that can enhance security while reducing the cost or complexity of security management – as well as security solutions that improve the management of IT itself – merit closer scrutiny for these values.
  • The crisis will increase the value of “security-as-a-service.” A now-dire need to move expenditures away from capex and more toward the opex side of the balance sheet presents a new opportunity for security offered as a service. Crawford notes that service-oriented approaches offer ways to keep up with the threat while getting a better-defined handle on the investment.
  • Get ready for “W3D” compliance. Just as SOX emerged from the previous major downturn, Crawford advises businesses to prepare for the inevitable wave of compliance with “W3D:” “What Washington (or the World) Will Do.”

“The greatest concern the financial crisis creates for IT security and risk professionals lies in the roots of the mess itself,” says Crawford. “If the inclination of the business is always to think first about IT’s primary mission, and only incidentally about the risks that may be exposed, security and risk management may never rise to the level needed to address the truly alarming level of malicious threats in today’s environment. Just as with illusory lending, however, we now have abundant evidence of the impact of poorly managed risk that should motivate us to do better.  The question is, will we?”

To purchase a copy of this advisory note visit: http://www.enterprisemanagement.com/research/asset.php?id=950

Share this:

  • Facebook
  • Twitter
  • LinkedIn
  • Email
  • More
  • Pinterest
  • Tumblr
  • Print
  • Reddit
  • Pocket
  • Instapaper

Related That May Interest You

Filed Under: IT Security Tagged With: IT Security

Popular Articles

  • 13 Sites to Download Free eBooks
  • 10 Certifications to Improve Your IT Career
  • How To Deal With Low Morale in The Workplace
  • 5 Ways to Stay Positive in Negative Situations
  • How Passion For Your Job Can Lead To Success
  • How To Work Under Pressure
  • How To Write IT Technical Documentation
  • How To Convert An Email Into An Outlook Task
  • How to Plan a 5S System Launch
  • A 5S Office System - Part 1 Planning
  • Leadership Skills – The Top 5 Skills Needed For IT Leadership Roles
  • 5S System Step 1 - The Sort Step

Latest Tweets

  • Agile project management: A comprehensive guide | CIO https://t.co/lNOtb5MYKB March 2, 2018 5:05 pm
  • The Skills Companies Need Most in 2018 – And The Courses to Get Them - LinkedIn https://t.co/l8fWcK2BvD January 28, 2018 4:45 pm
  • What You Need to Know About Interviewing in 2018 | Official LinkedIn Blog https://t.co/m1zGkCLgpo January 28, 2018 2:05 pm
  • 50 best small companies to work for of 2017, according to employees - Business Insider https://t.co/DeDU2AAb9t December 4, 2017 5:01 pm
  • 2017’s Best & Worst Places to Start a Career #Career https://t.co/9VLvFI5JIu October 21, 2017 7:15 pm
  • Which Is More Important: Faster RAM or More RAM? https://t.co/hPzgQlw1yd September 9, 2017 1:05 pm
  • Leadership training: 10 online resources for developing leadership skills | CIO https://t.co/NeGCSlTyx8 September 5, 2017 3:55 pm
  • If your Wi-Fi router is on this list it might be vulnerable to hacking tools. https://t.co/DCGjoqTXmD June 17, 2017 3:50 pm
  • OneDrive Files On-Demand now available for Windows Insiders https://t.co/l1wNO24Xsp June 17, 2017 12:45 pm
  • Win7 Monthly Rollup KB 4022719 triggers printing problems in Internet Explorer @ AskWoody https://t.co/DdB74SBCmL June 16, 2017 1:00 pm
  • Follow ITManagersInbox On Twitter
IT Managers Inbox Runs On The Magazine Theme

© Copyright 2008-2018 IT Managers Inbox · All Rights Reserved

loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.