Execs need to take cybersecurity seriously: Study

Friday, 02 April 2010, 00:00 IST
Printer Print Email Email
Execs need to take cybersecurity seriously: Study
Bangalore: Executives at top level should take cybersecurity more seriously or they will continue to suffer big losses, suggests a report called "The Financial Management of Cyber Risk." "Many organizations see cybersecurity as solely an IT problem. We are directing a wake-up call to executives nationwide. The message is, this is a very serious issue, and it's costing you a lot of money." said Karen Hughes, Director of Homeland Security Standards Programs at the American National Standards Institute (ANSI), one of the major sponsors of the new report, according to Channel World. The report cites a cyberpolicy review released by President Barack Obama's administration last May saying that U.S. businesses lost $1 trillion worth of intellectual property to cyberattacks between 2008 and 2009. That number doesn't include losses due to theft of personal information and loss of customers, the report said. The total cost of a typical breach of 10,000 personal records held by an organization would be about $2 million, the report said. "We believe if we can educate American organizations about how much they're actually losing, we can move to the next step, which is solving the problem," Clinton said. Eighty to 90 percent of cybersecurity problems can be avoided by a combination of best practices, standards and security technology, but some organizations need to understand the financial problems associated with poor security practices before they will make changes, Clinton said. A small percentage of company CFOs are directly involved in cybersecurity plans at their companies, and at many companies, most employees don't see cybersecurity as part of their jobs, Clinton said. "In American organizations, everybody has data," he said. "Generally, people don't think it's their responsibility to secure their own data. They think that's the job of the IT guys down at the end of the hall." The report recommends ways companies can deal with cyberrisk. Among the recommendations for top executives: Appoint a cyberrisk team, develop a cyberrisk management plan across all departments and develop a total cyberrisk budget.