IT execs feel the heat as security woes multiply

News
Aug 28, 20066 mins

With security threats increasing and regulation tightening, companies are demanding greater IT accountability – and that can mean being forced to walk the plank after a breach.

AOL fired a researcher and a manager last week, and CTO Maureen Govern resigned after the Dulles, Va., company posted data on search queries made by 650,000 AOL subscribers. Ohio University dismissed two senior IT people this month following news of five security vulnerabilities that exposed the sensitive records of 137,000 alumni.

Fallout from the Department of Veterans Affairs’ security debacle is ongoing. The agency fired the analyst who took home a laptop containing data on 26 million veterans that was stolen when burglars broke into his home. The ensuing examination of the agency’s security practices led to the departure of several other VA employees, including CISO Pedro Cadenas, who resigned last month.

More:our accountability forum.

One IT exec’s take on accountability

What do you think? Discuss in

Security accountability is long overdue, says John Pescatore, a security analyst at Gartner. When a series of worms hit in 2001 and paralyzed businesses, IT staff threw up their hands and blamed vendors. “Five years ago, nobody was responsible and nobody had authority,” Pescatore says.

That doesn’t fly today. If a company is spending 5% of its IT budget on security, it expects a payoff. “The business side of the organization has learned to live with accountability and is able to talk about revenues and returns,” Pescatore says. “IT is getting dragged there, too.”

It’s not always a reasonable position, says Khalid Kark, an analyst at Forrester Research. IT managers and security managers aren’t the ones setting corporate policies, yet they’re responsible for enforcing the policies and ensuring security, he says. Recent breaches have led to a surge in security consciousness in the executive suite, but it will take time to filter through the organization. “Meanwhile, corporate boards need to have a scapegoat, and they’ve got one.”

All in a day’s work

IT executives say their jobs are now on the line if an IT event compromises security or im­pedes business performance. They’re taking the heightened exposure in stride, however.

Greater accountability is a natural consequence of IT becoming more central to business operations, says Chris Majauckas, computer technology manager for Metrocorp Publications in Boston.

“Upper management is aware that it is impossible to foresee every possible negative event, but they do expect those events to be handled promptly and properly,” he says.

“The days of upper executives that aren’t IT-aware are gone,” adds Bruce Meyer, senior network engineer at ProMedica Health System in Toledo, Ohio. “They don’t need assistance to print out their e-mail anymore. They understand the business impact of not having systems working. It costs money, and they’re accountable for the bottom line. When things break they want to know why, and what was done to protect against it happening again.”

Ron Rose, CIO at Priceline.com in Norwalk, Conn., agrees. “As business people gain more experience with technology-driven enterprises, they want more specificity about results,” he says.

They also have a better understanding of the complexities of IT and the challenges of change management. “The bar is set a little higher each year, but the business people understand the challenges better each year as well,” he says. “If your goal has always been truly high-quality systems that are secure and auditable, things are pretty consistent.”

The negative publicity surrounding the recent breaches has forced all IT departments “to examine how the events happened and discuss with the executive level what our exposure to the same incident would be,” says Cory Elliott, IT director at Basic Energy Services in Midland, Texas.

Another driver is the regulatory environment. The Health Insur­ance Portability and Account­abil­ity Act (HIPAA) and the Sarbanes-Oxley Act (SOX) were designed to protect patient pri­vacy and im­prove financial re­porting, respectively. Compliance requires more secure, reliable IT systems and processes. The burden of providing that falls to IT – which can become a scapegoat if efforts come up short.

There is a greater level of scru­tiny on public companies, says Bernie Donnelly, vice president of quality assurance and control at the Philadelphia Stock Exchange, which plans to go public and is voluntarily complying with SOX in the meantime.

“Oversights, either deliberate or inadvertent, now become part of reports to audit committees and boards, who have obligations to show due diligence in responding to compromised situations,” he says. “This may produce more pressure and require dismissals that would not necessarily occur in private companies.”

Dismissing or shuffling IT staff is often a signal to the public that punitive and preventive measures have been taken, Donnelly says.

On the bright side, the same legislation that has raised IT accountability also is providing an opportunity for IT to solicit more funding to address security gaps.

ProMedica added a position – director of IT security – and aligned staff under the new director. The company’s IT department is spending more time and money on security investments such as intrusion-prevention systems, firewall, security appliances and anti­virus software. “Sure it was because of legislation – HIPAA in our case – but there’s the motivation of doing the right thing to keep things running as well,” Meyer says.

That’s a good approach, experts say. “If you have a regulatory stick, use it,” Pescatore says. Many organizations are subject to SOX and HIPAA rules, as well as state regulations such as California’s data-security law and industry mandates such as the Payment Card Industry data-security standard. Use those rules to point out and prioritize potentially criminal situations, he says.

While greater IT accountability is a good thing, it has to come with authority, Pescatore says. When IT people don’t have enough authority, their security laments can go unheeded.

“If you think you’re in a position with responsibility but no authority, you really ought to change your job, because you are going to be held accountable,” he says. “When something goes wrong you can’t say, ‘Well, yes, I was responsible but I didn’t have the authority to fix it or change it or make it happen.’ You’re toast.”

If you lack authority, it’s time to be proactive, Pescatore says. One tactic is to “go make friends with the auditing department,” he says. Many organizations have an internal audit department whose purview can include checking for security due diligence. Help auditors find the weak spots, Pescatore suggests, adding, “Management cannot ignore an audit report.”

If you don’t have an internal audit department, look for outside help. “Fight to get the funding to bring in an outside consultancy to do a security audit. Very often management will listen to an outsider who says the same thing an insider says,” Pescatore says.

What’s important to avoid is the Chicken Little scenario. “Don’t say, ‘Look, the sky could fall, the world could end,'” he says. Ground your assertions in reason: “It has to be about more than just fear.”

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author

Denise Dubie

Denise Dubie is a senior editor at Network World with nearly 30 years of experience writing about the tech industry. Her coverage areas include AIOps, cybersecurity, networking careers, network management, observability, SASE, SD-WAN, and how AI transforms enterprise IT. A seasoned journalist and content creator, Denise writes breaking news and in-depth features, and she delivers practical advice for IT professionals while making complex technology accessible to all. Before returning to journalism, she held senior content marketing roles at CA Technologies, Berkshire Grey, and Cisco. Denise is a trusted voice in the world of enterprise IT and networking.

More from this author