Sunday, May 16, 2021

How IT Departments Can Help Rather Than Hinder Security

The chairman and CEO of insurance holding company The Chubb Corp. is taking a strong stance on changing the way corporations devise and implement IT security and business continuity plans, an issue that has moved to the forefront since Sept. 11.

In a speech last week to IT executives and corporate risk managers at the Bureau of National Affairs’ (BNA) cybersecurity summit, Chubb’s Dean O’Hare said IT security planning must not be confined to information technology departments. He advocates that it rise to the corporate governance level, involving oversight by top executives and boards of directors.

“It is increasingly clear that we cannot manage these risks within any one silo. Cybersecurity must be an integral part of a company’s overall security planning,” O’Hare said in his speech to the BNA, portions of which were released by Chubb. “Information technology experts cannot do this alone. They must work with security, human resources, risk management, general counsel and line management across the entire enterprise to develop policies and procedures to minimize risks.”

More on Disaster Planning and Business Continuity

CIOs’ Business Continuity Plans Seen Falling Short

Disaster

Recovery: Lessons Learned From 9/11

META Report: The

New Logistics of Disaster Recovery

The

Importance of Disaster Recovery Planning Hits Home

Before

Trouble Strikes

Assuring

Business Data Continuity

CIO

Worries for 2002

O’Hare’s words should be welcome words to corporate IT executives, many of whom have sought for years to attract that level of attention and input — not to mention funding — from CEOs and directors for their IT security and business continuity plans.

Many Companies Still Taking Security Shortcuts

Although Sept. 11 has brought a renewed focus on devising robust security plans, many companies reportedly are still lagging on that front. A recent report by Gartner Inc. found that many companies remain focused on inexpensive tactics such as updating and testing their business-continuity plans, rather than making major changes, such as moving data centers or offices to more secure locations.

O’Hare also said in his remarks that there must be across-the-board cooperation between IT and other in-house departments, as well as cooperation among companies, industries and the public and private sectors when it comes to building security strategies.

O’Hare cited what he believes to be good examples of large-scale cooperative efforts aimed at boosting cybersecurity at the industry level. They include the National Association of Manufacturers’ Homeland Security Committee, which recently formed to help member companies understand key operational and policy issues such as cybersecurity, and the Critical Infrastructure Protection Board, formed by President Bush’s chief cyber security adviser, Richard Clarke, to improve coordination between federal agencies and businesses.

Among his other points:

  • Cooperation and trust between business and law enforcement is critical to thwarting e-security threats. He said a major problem is that too few companies report cyber crimes to the police or FBI, out of fear that negative publicity will hurt their business. O’Hare said: “When a company fails to reach out to law enforcement, it leaves itself more vulnerable to future crimes.”

  • Corporate execs have a strong personal interest to ensure their cyber security plans are as strong as possible: a threat of personal liability lawsuits from shareholders or businesss partners due to an IT security failure.

The Bureau of National Affairs (BNA) publishes news, analysis, and reference materials covering legal and regulatory developments for corporate and government leaders.

Similar articles

Latest Articles

How IBM has Changed...

Think is IBM’s big annual conference, and again this year, it was digital. I’m noticing a sharp quality difference in shows like this where...

Database-Tuning Platform Launches and...

PITTSBURGH — A team out of Carnegie Mellon University is launching its automatic database-tuning product today with the help of $2.5 million in funding.   OtterTune,...

Top 10 Professional Services...

Professional services automation (PSA) software aims to offer service-based companies most of the software they will need to run their businesses in one package....

What is Data Aggregation?

Data aggregation is the process where raw data is gathered and presented in a summarized format for statistical analysis. The data may be gathered...