IT security: The trends to watch in 2009

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

SaaS, Firewall, Cloud

ANALYSIS

In the arms race between security specialists and threats, it's hard enough keeping up with advisories, warnings of potential problems and new philosophies of safe IT, let alone mixing in the rapidly changing technological and economical implications of the connected environment.

The continuing economic downturn could lead to more instances of cybercrime, with a corresponding tightening of security budgets. That was the gloomy prognosis of security experts at a recent CSO interchange event, where chief security officers met to swap war stories and ideas. Cloud computing and the outsourcing of business IT processes are hot topics at the moment, as is virtualisation, due to the apparent cost-savings.

Andy Buss, senior analyst at Canalys, believes the current trend towards cloud computing and security software-as-a-service (SaaS) is likely to continue. "Cloud computing is starting to establish itself as viable. There are possibilities in security as a managed service," he says. "In-the-cloud firewalls and services allowing mobile workers to access cloud-based applications [are also likely]."

Buss expects to see more security applications being delivered virtually over SSL encrypted VPNs (virtual private networks) next year. This would not be a move to using thin clients, says Buss, but the use of virtualised applications to cut the costs of data replication.

People need to work out how they will link these virtual applications, provided by different vendors, into a common security network, he says. "We need services where everything you do follows company policy, to get more corporate control. Say you have Salesforce, hosted CRM from SAP, plus hosted email services — how do you protect all of those while providing mobile access?"

Buss also sees the use of managed email services increasing next year. Symantec's acquisition of MessageLabs in 2008, with Cisco buying IronPort and Google scooping up Postini in 2007, means more choice for enterprises thinking of countering email-borne threats through web services.

"There have been new technologies launched in web-threat security, while there are more and more interactions with the web," says Buss. "Companies need to be able to classify where emails are coming from — that could be by using web reputation or IP reputation."

Buss believes using web services to pre-clean files and applications could allow companies to get more performance out of their existing backend systems. He expects networking security also to be increasingly important to businesses in the coming year.

"As we see a move towards higher bandwidth usage, we'll need more distributed security in the network," he explains. "People want to embed security in the router, as close to the metal as they can."

Talkback

Cybercrime and outsourcing were named top security concerns according to a new study conducted by The Ponemon Institute. The survey found that 50% of IT operations professionals viewed outsourcing as an imminent and near-time critical risk, while more than 75% of IT security professionals noted cybercrime a major issue - despite concerted efforts to thwart hackers in recent years. In tandem, survey results highlighted an increase in shared thinking between traditionally disparate IT functions within the organisation - IT operations and IT security.

With the emergence of consumer technology in the workplace, coupled with social networking and Web 2.0 technologies and the increased sophistication of cyber criminals, truly securing an organisation's IT environment is an uphill battle In the next year or two, these challenges will increase in both the breadth and depth of threats - the companies surveyed made this very clear. The key for both IT operations and IT security is to find the common ground necessary to better-wage this security battle together.

Given the breadth and depth of security breaches spanning the globe this year - all of which have had a long-lasting negative impact on organisations and consumers alike - IT security and IT operations professionals have an increasingly critical task at hand, to protect sensitive data wherever it lives in an organisation.

The survey was developed to better understand if certain publicised IT risks to personal and confidential data are truly a concern for organisations in the next two years. Based on interviews with IT experts in operations and information security, the following eight mega trends rose to the top: cloud computing; virtualization; mobility and mobile devices; cybercrime; outsourcing to third parties; data breaches and the risk of identity theft; peer-to-peer (P2P) file sharing and Web 2.0.

Key Findings from the 2008 Security Mega Trends Survey include:

* Outsourced IT is a Major Concern: As companies look to reduce costs based on economic factors in 2009, outsourcing will continue to be an attractive option for efficiency gains. The security risks associated with outsourcing are tremendous according to survey data. The top risks posed by outsourcing according to IT security (50%) and IT operations (59%) respondents is the exposure of sensitive information to third parties and the threat that that data will be improperly protected in transit.

* Data Breaches and Cybercrime are on the Rise: Survey results indicated that the biggest concern relative to data loss is the threat of data making it into the hands of cyber thieves (46% for IT security and 24% for IT operations), thus wreaking continued havoc not just on the customers whose data was stolen but also on the organisations responsible for that lost data. IT survey participants reported that 92% of the organisations have experienced a cyber attack. The injury to corporate brands as a result of a major data loss incident is critical, especially in an economic downturn
Workforce Mobility Contributes to Data Loss: IT security and IT operations' respondents (96% and 91% respectively) agree that employee mobility introduces a significant threat to securing corporate data as it diminishes IT's ability to properly identify and authenticate remote users on the network.

* Emerging technologies - Web 2.0, P2P, virtualization and cloud computing - are growing in prevalence with Cloud computing causing the most concern: The influx of new technologies - both business and consumer technologies - has opened additional avenues for cyber thieves to steal trade secrets and confidential business information. Cloud computing came out on top with 61% of respondents ranking it as a major security concern among the emerging technology trends. Virtualization was perceived as the least concerning at this time, though survey respondents cited all of these types of technologies as key concerns in the next year, where the increased risk to expose sensitive data ranked highest among both respondent groups.

lumension 24 December, 2008 19:51
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Schofield

Moonlight wasn't a Microsoft product, so it's not really a failure for Microsoft, more a failure for open source. Or, specifically, for Novell,...

1 hour ago by Jack Schofield on The future of .NET (Mono) on non-Windows platforms
J.A. Watson

@apexwm - You are basically right. GIMP is not included in the Fedora 17 base distribution, but it can be installed from the Add/Remove Software...

2 hours ago by J.A. Watson on Fedora 17 - The "Beefy Miracle" Arrives
Moley

@pjc158 Unfortunately our government signed away any such possibility in a entirely unequal treaty with the USA, purportedly in response to...

2 hours ago by Moley on Judge orders US to share MegaUpload evidence
J.A. Watson

@Thomas - Thanks for the tip, based on what you said I went back and downloaded the KDE spin, and installed that one another netbook (NF310). You...

2 hours ago by J.A. Watson on Fedora 17 - The "Beefy Miracle" Arrives
apexwm

JW, Thanks as always for the great review on these new releases. One thing that I've also read is that Fedora 17 will include GIMP 2.8 which is...

3 hours ago by apexwm on Fedora 17 - The "Beefy Miracle" Arrives
SoapyTablet

'Cut Price' Data Roaming? The price has been cut, but it is certainly not 'cut price' in the sense of the phrase, and nowhere near local EU data...

4 hours ago by SoapyTablet on Cut-price data roaming gets all-clear for July
apexwm

BrownieBoy: "Such crashes are normally down to the OS and/or a rogue application, which could be fixed by re-imaging. Everybody knows how Windows...

5 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Thomas Gellhaus

I've just started using it too, and like you I feel that Fedora is a fine GNOME 3 showcase distribution. I am torn, though, because I checked out...

5 hours ago by Thomas Gellhaus via Facebook on Fedora 17 - The "Beefy Miracle" Arrives
pjc158

Why is it that Newzealand has the guts to stand up to the USA and ask to see the evidence and we don't!

5 hours ago by pjc158 on Judge orders US to share MegaUpload evidence
Dean Talboys

What a farce! Hopefully the European court will see where this is leading.

8 hours ago by Dean Talboys via Facebook on Assange loses extradition battle in Supreme Court
SoapyTablet

Wouldn't surprise me if Samsung actually really had problems producing the white model (as Apple did - it would make more sense) and this non-story...

8 hours ago by SoapyTablet on Samsung Galaxy 'S3' delayed by special paint
Lonnie

those conformation letters are hard to figure out what is which letters it is a pain in the back side. Please make it more Ledge-able being better...

12 hours ago by Lonnie on Screenshots: Photoshop CS6 Beta
BrownieBoy

"cites" even. Ouch!

19 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Horace Ontalhold

...... and PDP11s too

19 hours ago by Horace Ontalhold on Fusion-io lays minefield with a billion IOPS
BrownieBoy

I had a quick skim through the PDF. It seems to be that many of these so-called cost savings would be down to a hardware refresh. Although...

20 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
bobandroid

496,999 BT Fon Hotspots lovingly situated in your next door neighbours garden, no matter how you dress that up its still a pup... Not where I need...

22 hours ago by bobandroid on London Olympics: BT needs 25,000 more Wi-Fi hotspots
apexwm

Jack : I was hoping you could provide us a summary since you are familiar with this report. I am not yet sure how much of my time I'd like to...

24 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Smilig Eddie

2 – 4 more weeks of waiting: how many buyers are going to decide instead to see what the iPhone 5 offers? Consumer trust in the brand has also...

1 day ago by Smilig Eddie on Samsung Galaxy 'S3' delayed by special paint
SRist

So it looks like this was a complete red herring - Adobe are allowing upgrades from Photoshop CS3, CS4 and CS5 at the same price. When did this...

1 day ago by SRist on Photoshop users attack Adobe upgrade policy change
Jack Schofield

@apexwm Have you considered either (a) reading the story above or (b) reading the PDF? There are answers in both.

1 day ago by Jack Schofield on Using Windows XP is a waste of money, says IDC