May 13, 2002—A new survey by Ernst & Young LLP, indicates that financial and reputational risk will increase as Information Technology (IT) connectivity increases, and that global economic uncertainty poses new risks that companies must quickly identify and address.
These findings stem from the results of Ernst & Young’s 2002 Global Information Security Survey, the first of two studies based on a analysis of many of the most information intensive companies in the world. Respondents indicate significant gaps in security management around critical business systems and data, despite awareness and recognition of the threats. The survey results also indicate that while information security has become a major concern for companies around the world, approaches to the risks are inconsistent and often insufficient.
Despite the continued threats, only 53% of companies have business continuity plans in place. In fact, 40% of companies do not even investigate information security incidents, an essential component to basic information security measures. These results indicate information security is still widely regarded as a technical issue, not a business issue, resulting in technology solutions without supporting business processes. This fundamental gap could potentially cause organizations to prepare inadequately for threats that are increasingly sophisticated and rapidly changing.
The survey continued media headlines of security breaches and virus infections, and the tragic events of September 11th, is based on interviews with over 450 CIOs, IT Directors and business executives worldwide and was developed to understand their views on information security and how they are responding to threats.
Of these respondents, 60% indicate that they expect to experience greater vulnerability as connectivity increases. In addition, a majority of respondents also indicate that critical business systems are increasingly interrupted— 75% experience unexpected unavailability.
Employee awareness of information security policies and procedures is cited by two-thirds (66%) of the respondents as a barrier to achieving effective security, yet less than half of those surveyed have employee awareness and training programs in place that address these critical security policies. What’s more, respondents indicate a greater concern about vulnerability to external attacks (57%) than internal (41%), despite published data that indicates that more than three-quarters of attacks originate from within organizations.
For more information as well as an in-depth analysis of the survey, contact Ernst & Young.