Latest news

The study surveyed senior managers at 600 mid-sized (250 – 2,500 employees) European businesses in the UK, France, Germany, Hungary, the Netherlands and Spain to compile Europe’s first Information Risk Maturity Index.
The Index was based on a set of measures that, if put in place and frequently monitored, would help protect the information held by an organization. Of the six countries included, the UK consistently fared the worst, achieving a score of only 55.08 against a target of 100.
While there was no stand-out performer in Europe, Hungary outperformed the other European countries with the highest overall index score of 61.
“It’s a surprise that UK businesses fared so badly in this study, particularly when high-profile data breaches receive such widespread media attention in the UK, seriously damaging brand reputation,” said Christian Toon, head of information risk at Iron Mountain Europe.
“The findings reveal that though many British businesses do have a data protection and information risk strategy in place, most fail to monitor its effectiveness. In Hungary, with its high level of ISO certification, businesses are more likely to have training programs, clear guidance, codes of conduct and employee communication programs in place. This difference underscores why companies need to adopt a culture of Corporate Information Responsibility (CIR). This shift is key to protecting sensitive information," Toon added.
While some countries performed better than others, the results suggest that there is a problem across the board with the way businesses regard information risk. Too few see the risk as a serious threat to their business. Addressing this shortcoming must start from the top.
Christian Toon provides the following practical advice to help businesses become more responsible in protecting information.
Make it a boardroom issue:
- Make information risk a permanent point on the Board agenda
- Articulate information risk in a language the Board can relate to – highlight, for example, the financial implications of not safeguarding information
- Include information risk on your register and provide regular status reports to the Board
- Embed it into your existing practices and create monthly dashboards to monitor progress.
- People are the weakest link – screen all applicants before offering employment with background checks. Rescreen at regular intervals
- Design and run information risk awareness programs that start at induction and are followed-up with annual refresher courses
- Reinforce good behaviors by rewarding them and sanction poor behavior
- Build information risk into staff objectives and embed these into annual performance reviews
- Identify technology that is fit for purpose and secure enough for your needs. When it is implemented, maintain it, and ensure that you get sufficient logs and records from your systems
- Finally, don’t underestimate the change possible with even minimum investments in time and budget. Simple measures and minor investment, which will not take the focus away from the core business, can move the organization towards more secure information management.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





