Bosses 'too trusting' of outsourcer's security

By Jo Best, silicon.com
08 October 2004 02:36 PM
Tags: trusting, managers, bosses, care, too, take, outsourcer, taking
CEOs aren't taking the care that they should with their customers' data when they outsource, according to a new survey of senior management.

The Ernst & Young Global Information Security Survey queried 1,233 companies from 70 countries and found that most were trusting their outsourcer's security to chance rather than actively tracking how secure data is.

Of those questioned by Ernst & Young, 70 per cent of companies fail to regularly audit their outsourcer to see whether it comes up to the same security standards of those of its employer and 80 per cent don't measure if their outsourcers are compliant with the same regulatory standards as they are.

Industry's lack of security-savvy is placed firmly at the door of the higher-ups.

"As more organisations enter into close collaboration with other organisations, the less likely that senior management truly comprehends the organisation's ever-growing risk dependencies," the report says. "Senior management is more trusting than prudent."

Although execs might be trusting of the sanctity of their outsourcers, they have equal faith that their own organisation is protecting its data safely.

In the event of a "serious disruption", 10 per cent of those queried thought their employers would be able to continue operations and 14 per cent had the same confidence an offshore operator could do the same.

However, few bosses have the facts and figures in front of them to know whether their firm has got its data in the digital equivalent of a cardboard box or Fort Knox, with nearly 70 per cent of boards not receiving an update on their company's security status and some 20 per cent of those queried saying they didn't think that their businesses thought security was a CEO-level priority.

"Organisations apparently continue to rely on luck rather than proven information security controls," the report says.

Bosses may be in the dark when it comes to security but they'd like their partners to be more so, it seems. Fifty-five per cent of respondents said they wouldn't tell their business partners about any security glitches for fear of "a negative impact on their competitive stance, public image and stock value".

Advertisement

Talkback 0 comments

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured