With security threats increasing and regulation tightening, companies are demanding greater IT accountability – and that can mean being forced to walk the plank after a breach.
AOL fired a researcher and a manager last week, and CTO Maureen Govern resigned after the Dulles, Va., company posted data on search queries made by 650,000 AOL subscribers. Ohio University dismissed two senior IT people this month following news of five security vulnerabilities that exposed the sensitive records of 137,000 alumni.
Fallout from the Department of Veterans Affairs’ security debacle is ongoing. The agency fired the analyst who took home a laptop containing data on 26 million veterans that was stolen when burglars broke into his home. The ensuing examination of the agency’s security practices led to the departure of several other VA employees, including CISO Pedro Cadenas, who resigned last month.
More:our accountability forum.
One IT exec’s take on accountability
What do you think? Discuss in
Security accountability is long overdue, says John Pescatore, a security analyst at Gartner. When a series of worms hit in 2001 and paralyzed businesses, IT staff threw up their hands and blamed vendors. “Five years ago, nobody was responsible and nobody had authority,” Pescatore says.
That doesn’t fly today. If a company is spending 5% of its IT budget on security, it expects a payoff. “The business side of the organization has learned to live with accountability and is able to talk about revenues and returns,” Pescatore says. “IT is getting dragged there, too.”
It’s not always a reasonable position, says Khalid Kark, an analyst at Forrester Research. IT managers and security managers aren’t the ones setting corporate policies, yet they’re responsible for enforcing the policies and ensuring security, he says. Recent breaches have led to a surge in security consciousness in the executive suite, but it will take time to filter through the organization. “Meanwhile, corporate boards need to have a scapegoat, and they’ve got one.”
All in a day’s work
IT executives say their jobs are now on the line if an IT event compromises security or impedes business performance. They’re taking the heightened exposure in stride, however.
Greater accountability is a natural consequence of IT becoming more central to business operations, says Chris Majauckas, computer technology manager for Metrocorp Publications in Boston.
“Upper management is aware that it is impossible to foresee every possible negative event, but they do expect those events to be handled promptly and properly,” he says.
“The days of upper executives that aren’t IT-aware are gone,” adds Bruce Meyer, senior network engineer at ProMedica Health System in Toledo, Ohio. “They don’t need assistance to print out their e-mail anymore. They understand the business impact of not having systems working. It costs money, and they’re accountable for the bottom line. When things break they want to know why, and what was done to protect against it happening again.”
Ron Rose, CIO at Priceline.com in Norwalk, Conn., agrees. “As business people gain more experience with technology-driven enterprises, they want more specificity about results,” he says.
They also have a better understanding of the complexities of IT and the challenges of change management. “The bar is set a little higher each year, but the business people understand the challenges better each year as well,” he says. “If your goal has always been truly high-quality systems that are secure and auditable, things are pretty consistent.”
The negative publicity surrounding the recent breaches has forced all IT departments “to examine how the events happened and discuss with the executive level what our exposure to the same incident would be,” says Cory Elliott, IT director at Basic Energy Services in Midland, Texas.
Another driver is the regulatory environment. The Health Insurance Portability and Accountability Act (HIPAA) and the Sarbanes-Oxley Act (SOX) were designed to protect patient privacy and improve financial reporting, respectively. Compliance requires more secure, reliable IT systems and processes. The burden of providing that falls to IT – which can become a scapegoat if efforts come up short.
There is a greater level of scrutiny on public companies, says Bernie Donnelly, vice president of quality assurance and control at the Philadelphia Stock Exchange, which plans to go public and is voluntarily complying with SOX in the meantime.
“Oversights, either deliberate or inadvertent, now become part of reports to audit committees and boards, who have obligations to show due diligence in responding to compromised situations,” he says. “This may produce more pressure and require dismissals that would not necessarily occur in private companies.”
Dismissing or shuffling IT staff is often a signal to the public that punitive and preventive measures have been taken, Donnelly says.
On the bright side, the same legislation that has raised IT accountability also is providing an opportunity for IT to solicit more funding to address security gaps.
ProMedica added a position – director of IT security – and aligned staff under the new director. The company’s IT department is spending more time and money on security investments such as intrusion-prevention systems, firewall, security appliances and antivirus software. “Sure it was because of legislation – HIPAA in our case – but there’s the motivation of doing the right thing to keep things running as well,” Meyer says.
That’s a good approach, experts say. “If you have a regulatory stick, use it,” Pescatore says. Many organizations are subject to SOX and HIPAA rules, as well as state regulations such as California’s data-security law and industry mandates such as the Payment Card Industry data-security standard. Use those rules to point out and prioritize potentially criminal situations, he says.
While greater IT accountability is a good thing, it has to come with authority, Pescatore says. When IT people don’t have enough authority, their security laments can go unheeded.
“If you think you’re in a position with responsibility but no authority, you really ought to change your job, because you are going to be held accountable,” he says. “When something goes wrong you can’t say, ‘Well, yes, I was responsible but I didn’t have the authority to fix it or change it or make it happen.’ You’re toast.”
If you lack authority, it’s time to be proactive, Pescatore says. One tactic is to “go make friends with the auditing department,” he says. Many organizations have an internal audit department whose purview can include checking for security due diligence. Help auditors find the weak spots, Pescatore suggests, adding, “Management cannot ignore an audit report.”
If you don’t have an internal audit department, look for outside help. “Fight to get the funding to bring in an outside consultancy to do a security audit. Very often management will listen to an outsider who says the same thing an insider says,” Pescatore says.
What’s important to avoid is the Chicken Little scenario. “Don’t say, ‘Look, the sky could fall, the world could end,'” he says. Ground your assertions in reason: “It has to be about more than just fear.”




