Home > Midmarket CIO Tips > Security for the midmarket > Security's crystal ball for 2008
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Security's crystal ball for 2008


Mike Rothman, Contributor
12.27.2007
Rating: -4.33- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


It's the holiday season, and that means it's time for all of those pundits out there to start gazing into their crystal balls and figuring out what's going to happen in the coming 12 months. I'm a pundit, too, and given the amount of change in the security business over the past 12 months, 2008 is sure to be eventful.

The old adage for security practitioners is that we want our days to be "uneventful." A good day is a day where nothing happens. So the amount of turmoil in 2007 was certainly unwelcome. But before we delve into the future, let's take a quick look at what happened in 2007. It can be summed up in three words: TJX, PCI and bots.

The bad guys (and gals) have been focused almost exclusively on stealing private information, which was readily apparent when the true depth of The TJX Cos.' data breach came to light early in the year. It's likely that more than 100 million customers will have been compromised, and the ramifications to the banks and retailers will be felt for years to come. You can't mention TJX without discussing the Payment Card Industry (PCI) standard, either. The depth of the TJX breach is positioned to give some teeth to the PCI regulation. We'll talk about that more later.

Finally, 2007 will be remembered as the year of the bot. These compromised machines have been doing the dirty work of the organized cybercrime rings all year. So the objective now is to not just steal personal information, but also to turn the machine into a drone that sends spam, launches denial-of-service attacks and tries to compromise other machines virally.

So let's jump into 10 things I think midmarket technologists need to think about in 2008:

1. Users are still the weakest link: In 2008 midmarket firms should start to realize that users are the last line of defense and focus on security education to keep them from continuing to do stupid things.

2. Web apps provide the path of least resistance: With


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security for the midmarket
Locking down security in the move to electronic medical records
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Stopping malware viruses from attacking Web 2.0 technology
Virtual servers no escape from IT security management concerns
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
Risk assessment frameworks easy to employ
Midmarket regulatory compliance management: Don't let your guard down

Information security management for the midmarket
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted
Gartner: Vetting security of third-party partners in five steps
Locking down security in the move to electronic medical records
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
Information systems management for the midmarket
CIOs share advice on doing more with less
Get smart about patching security vulnerabilities
A CIO's advice for implementing single sign-on solutions

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


70% to 80% of new attacks already being targeted at the application layer, the difficulty in actually securing those applications comes to light. Midmarket companies need to watch their applications carefully because there is no telling when a new exploit will emerge.

3. PCI becomes real: As discussed relative to the TJX data breach, the banks and credit card processors should become a lot more serious about making sure midmarket retailers keep private data private.

4. Endpoint security integration simplifies desktop defense: Midmarket folks will finally have enough of the multitude of agents that run on the desktop and don't seem to keep them secure. So the idea of an integrated agent that provides multiple security functions is very interesting.

5. Security services become a real option: With Google offering Postini email security services as part of its Google Apps Premium offering, managed security services will start to hit the masses.

6. Network access control (NAC) is still a disappointment: Midmarket companies will be a couple of years behind large enterprises in rebuilding their campus networks in a more secure fashion. Yet all midmarket companies will hear in 2008 is how important it is to think about NAC right now.

7. Security management doesn't get better: Midmarket IT manages will continue to be perplexed about what's happening in their environments. Security information management is still a bust for midmarket customers, although log management is an area for further investigation.

8. Midmarket firms look to "poor man's DLP" to address data leakage: As opposed to worrying about a full, broad data leak protection suite, midmarket CIOs will look to build in capabilities of their Web filtering and email security offerings to look for Social Security numbers and other private data.

9. The perimeter continues to erode: With more mobility and increasing business process integration, midmarket companies continue to struggle in defining who is actually supposed to be on the network at any given time. So security must continue to move further into the network and start focusing on protecting data.

10. Disk encryption happens: Given the impact of continuing to lose laptops with private data, midmarket companies will increasingly just start encrypting laptops with whole disk encryption products. Over time this capability settles into the endpoint security suite, but not until 2009.

We can certainly hope for an uneventful 2008, but the odds of that aren't good. Thus, midmarket security professionals must continue to focus on closing off their most exposed flanks and trying to stay one step ahead of the bad guys.

Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and the author of The Pragmatic CSO: 12 Steps to Being a Security Master. Get more information about The Pragmatic CSO at www.pragmaticcso.com, read his blog at http://blog.securityincite.com, or reach him via email at mike.rothman (at) securityincite (dot) com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts