Security attacks on IT systems more than doubled, says Deloitte & Touche survey

June 4, 2004—External security attacks on information technology systems at a sampling of the world’s leading financial institutions more than doubled from a year ago, according to responses from a global survey of financial institutions by Deloitte & Touche.

Deloitte’s 2004 Global Security Survey revealed that 83 percent of survey respondents acknowledged their systems had been compromised in the past year, compared to 39 percent in 2003. Moreover, 40 percent of respondents whose systems were attacked said they sustained financial losses.

The survey, which provides insight into the state of security in the financial services industry, consisted of interviews with senior security officers from 100 of the top global financial institutions.

Despite the reported doubling of security attacks, more than a quarter of financial institutions said their security budgets remained flat, while nearly 10 percent had their budgets slashed from the previous year. Respondents reported that they perceived their spending on security to be in line with other comparable organizations and in line with their own security plans.

The survey also showed declining use of security technologies. With more than 70 percent of respondents stating they believed viruses and worms to be the greatest threat to their systems within the next year, a total of 87 percent of respondents said they have fully deployed anti-virus measures. This result is down from a response rate of 96 percent from last year’s survey.

There is, however, encouraging news. Financial institutions responding showed improved regulatory compliance efforts, with two-thirds indicating they now have a program for managing privacy, compared to 56 percent of respondents in 2003. In addition, nearly seven of 10 felt that senior management is committed to security projects needed to address regulatory requirements.

Additional key findings of the survey include:

  • Although more than half indicated that security is a key part of their solution, 10 percent reported that their general management perceived security as a business enabler.
  • The majority of respondents indicated they have a comprehensive IT disaster recovery plan in place, but only half included personnel within their business continuity plans.
  • One-third of respondents stated they believe that security technologies acquired by their organizations are not being utilized effectively.
  • Only one quarter of respondents felt that their strategic and security technology initiatives were well aligned.
  • Identity management and vulnerability management were the two most common technologies that financial services are piloting or intend to deploy over the coming 18 months, according to the survey.

The survey, conducted in face-to-face interviews by Deloitte’s Global Financial Services Industry practice, focused on senior information technology executives (Chief Information Officer, Chief Security Officer, Security Management Team, etc.) from 100 of the top global financial services organizations.

For more information, contact Deloitte.

Topics

Share this article

LinkedIn
Instagram Threads
  Featured Jobs
FM Link logo