Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Companies leaving the security of their data on cloud to chance, shows research by PwC/Infosecurity Europe

April 2012 by PwC/Infosecurity Europe

Only 38% of large organisations ensure that data held by external providers is encrypted

56% of small businesses don’t check their external provider’s security
Half of organisations of national importance use cloud for business critical data

Most organisations are now using cloud computing in one form or another, yet businesses are omitting to check out the security controls surrounding their data.

These are some preliminary findings from the 2012 Information Security Breaches Survey (ISBS) written by PwC in conjunction with Infosecurity Europe and supported by the department for Business, Innovation and Skills. The results will be revealed in full at Infosecurity Europe on 24 April following a speech by BIS minister David Willetts in the keynote theatre.

Although three-quarters (73%) of organisations are using at least outsourced service over the Internet, only 38% of large organisations ensure that data being held by external providers is encrypted. Furthermore, 56% of small businesses don’t carry out any checks of their external providers’ security and rely instead on contracts and contingency plans.

Chris Potter, PwC information security partner, said:

“The Internet continues to facilitate more sophisticated business relationships. Businesses are putting their faith in third parties to take care of their data but many are taking a laissez faire attitude to the security element. Not only are they often completely leaving the security controls to third parties, they are not actually checking what controls those third parties have in place.

“Small businesses may think that because their data is being hosted by a large cloud provider that good security controls will be in place, but this isn’t necessarily the case. Companies should always check what security controls their providers are operating.”

Around a quarter of large organisations and one-fifth of small ones have extremely confidential data hosted on the Internet - with website, email and payment service provision the most commonly used cloud services. Half of organisations of national importance, such as financial services, telecommunications and utilities, critically depend on them.

Many small businesses rely only on a contingency plan to move the outsourced service if there are issues. Yet, a third of contingency plans to deal with systems failure and data corruption prove ineffective. The survey shows a strong correlation between the effectiveness of contingency plans and the seriousness of breaches. When contingency plans do work, less than half the incidents were serious; when the plans failed, four-fifths were serious.

The biggest blind spot in contingency planning is the infringement of laws and regulations, where only a fifth (18%) of affected organisations had a contingency plan. Further to this, 45% of large organisations breached data protection laws in the last year and this happened at least once a day at one in ten of them. After the most serious breaches, organisations improved their processes and technology and also trained their people. This reinforces the evidence that the worst security breaches are due to multiple failures in a combination of people, process and technology.

Chris Potter, PwC information security partner, said:

“Too many contingency plans are currently ineffective. Organisations should be frequently stress-testing their plans, especially because the survey shows a direct correlation between contingency planning and the severity of breaches. Rather than relying on contingency plans, organisations would be in a much more powerful position if they secure their data in the first place.”


See previous articles

    

See next articles












Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts