UK businesses are still failing to implement effective email and internet policies that could protect them from downtime, virus attacks and even costly legal action. Much of the problem is down to out-of-date policy and ignorance of the threats faced.
Companies who spend excessively on securing the perimeter, for example, may not have realised the greatest risk to their business is posed by the loss of intellectual property from within, as staff ferry portable devices in and out of the company...
This needs to be enforced by the CEO and the board, with organisations aspiring to implement well designed controls and fostering a security-conscious culture led from above. Without this top-down endorsement, employees will often ignore controls...
Naturally, the method needs to be repeatable because threats will change and controls therefore need to be reviewed. As Dave Martin, principle information security consultant at LogicaCMG, puts it: "If you haven't undertaken risk analysis, then how...
Threats to the hypervisor are currently minor - there haven't been many attacks to date, although they will come. He said: "We reduce the scope of threats because we reduce the attack surface of the operating system.
We invest up to 90 per cent of our security resources on controls and monitoring against internal threats. Employees and insiders are bigger threats to corporate security than external threats such as denial of service attacks or malware.