by Joel Shore

Security Summit

Feature
Nov 1, 200410 mins

CIOs gather at Dartmouth College to share ideas on enterprise security.

Can security be a competitive advantage? Are security and privacy at odds with speed and collaboration? How has Sarbanes-Oxley complicated the security challenge? And how do you balance risk and security?

Those are just some of the pressing questions 23 prominent IT executives and academics addressed at a recent daylong executive roundtable at Dartmouth College in Hanover, N.H.

The Thought Leadership Summit on Digital Strategies is an ongoing series of discussions for Fortune 500 CIOs and vice presidents focused on the business issues they face and the enabling role of IT. The summit was co-founded by the Center for Digital Strategies at Dartmouth’s Tuck School of Business and Cisco. Network World President and Editorial Director John Gallant moderated the event.

Participants represented some of the largest and most well-known companies in the U.S., including Fidelity, Staples, Citigroup, Owens-Corning, IBM, General Motors, Hasbro and Cisco . On the academic side, Harvard Business School, Bentley College, Dartmouth College and the Tuck School were represented.

The executives shared with peers their security fears, goals, frustrations and challenges. The many challenges include protecting the network against internal and external attacks, educating and training employees on security, obtaining adequate funding from the CEO and board of directors, complying with new federal regulations, and making sure they don’t impede the company’s business units.

“I never want to be in a position that the business wants to do something and I’m constraining it,” said Max Ward, vice president of technology at Staples.

There was widespread agreement on that point, but several participants noted that sometimes they can’t avoid it. IT staffers are often so busy putting out fires, fighting viruses and applying patches that they don’t have time to think about ways to make the business function better.

The issue becomes even more complex when you’re talking about the extended enterprise. “As we extend the enterprise out to the suppliers, having to deal with security and validating that this guy is trusted . . . it’s slowing that process down, but we have to do it. There’s no way around it,” said Doug Schwinn of Hasbro.

John Moore of IBM concurred. “You really want to be able to tie two networks together to have that free flow of information, but if Company A doesn’t have the same security standards that your company has, you’re really opening up your door to everything that wants to come in.”

The emphasis on security also can slow innovation, Fidelity’s Jim MacDonald said. Fidelity likes to work with small, innovative tech companies that can “help us get a competitive advantage.” But, if the company’s security standards are not up to snuff, “we’ve gone slower creating partnerships with those types of companies.”

M. Eric Johnson, director of Tuck’s Center for Digital Strategies, said information security is being treated today in a similar way that “quality” was treated 20 years ago: bolted on not built-in, viewed as an inhibitor of operations and residing in a “special” department. “It must move to being designed in at the start, being an enhancer of operations and internalized throughout the company,” he said.

The security advantage

On the question of whether stellar security can be a competitive advantage, most took the position that security is a prerequisite for doing business, but not necessarily something a company trumpets in the marketplace.

“Failure in security, that’s what gets noticed. If you’re successful, it’s expected,” said Jack Matejka of Eaton.

Hasbro’s Ed Kriete took a similar tack. “If you screw it up, there’s going to be real consequences, but at this point, it’s really a qualifier.”

Staples’ Ward disagreed, saying one of the reasons the office supply store is taking market share from its competitors is that it has convinced customers that “the system is going to be there when I need it.”

Threat matrix

Unfortunately, in today’s world, every company is a target and two problems weighing heavily on IT executives are trying to identify where the threats are coming from and trying to assess and analyze risk.

For these IT folks, the fear factor is real. “What I worry about is emerging threats that I don’t know about,” Fidelity’s MacDonald said.

Don Kosanka of Owens Corning has dealt with unsecure applications that were written when factories were isolated from the rest of the world and not connected to the supply chain.

For John Cianci of IBM, a big issue is protecting servers in IBM’s labs.

Cisco’s Brad Boston faced a similar situation: “We had to isolate all the labs. They were my biggest source of denial-of-service attacks.”

Other concerns are employees who connect from home over broadband or who use wireless connections, and employees who mix personal and corporate data on their personally owned BlackBerries and PDAs.

When it comes to analyzing risk, Fidelity has a solid approach. MacDonald uses a cyberthreat matrix, with the likelihood of a security event on one axis and the potential effect on the other. “The top right quadrant is our best analysis of what requires immediate attention and what senior executives should focus on,” he said.

Owens Corning uses a similar process to assess risk for its manufacturing plants, Kosanka said. “When you look at a manufacturing facility, you try to understand the probability of a failure and the impact of that failure. Looking at those two factors, you make decisions about how much you’re willing to invest,” he said.

Regulatory concerns

Federal regulations, particularly the Sarbanes-Oxley Act, are a major headache, according to the IT leaders. They said they were especially bothered by the lack of predictability and uniformity in terms of what is required to meet the regulations and in how those regulations are interpreted by auditors.

Hasbro’s Schwinn described the process as onerous and complained that it’s difficult to get a clear understanding of what the law requires. “The goal line keeps changing,” he said.

Staples’ Ward put it this way: “It’s like nailing Jell-O to the wall. The nature of that legislation is that it lends itself to people panicking and probably doing too much and still not knowing if they are going to be compliant. And it’s probably going to change over time. Whatever you get audited this year, it’s going to be different next year.”

“We use different” auditors, Cisco’s Boston said. “One to tell us how to do it, and the other to test it to do it right.”

Schwinn added, “Every auditor looks at it differently too. I actually had one level of review the other day. We were reviewing disaster-recovery components, and we had our plan. We had documented that we did the test but then the auditor says, ‘Prove to me that the document is authentic.’ How do we do that?”

Boston argued that while recent financial scandals spurred these regulations, “none of these controls will prevent Enron or the next WorldCom because it has nothing to do with what happened.”

International regulations with regard to security and privacy add another level of complexity. IBM’s Cianci said Italian privacy laws require customers to opt in before a company can send them e-mail. “If you don’t know about it, your chief officer in Italy is going to jail,” he said.

European Union privacy and security laws have slowed Hasbro’s business initiatives, said Michael Elliott, because each country interprets the regulations differently.

For other issues, such as ways to decrease complexity, there are no easy answers. Some panel members said they would like to reduce the number of vendors they deal with, but worry about creating a single point of failure or becoming too dependent on one vendor.

Many spoke about the desire to move off the Microsoft monoculture and spread their risk among multiple platforms, but there was agreement that such a strategy at this point was untried and risky.

The metric system

Similarly, the IT executives said they struggle with finding metrics to determine whether they are spending too much or too little on security.

Scott Day, global information protection manager at Cargill, said that determining how much you’re spending is difficult. “Do you count directory services in your security budget? Do you do ID access in your security budget? In my opinion, there is a wide range of debate. You take all that and blend it together, you get a target for what you think you as a corporation need. You go to your sponsors and stakeholders and say, ‘Here’s why we’re reaching that level and here’s what we’re doing from a financial standpoint.’ Either they’re happy with it or they’re not,” he said.

There are limits to how much you can ask for, Staples’ Ward said. “We know we need to do things, [but] I am not going to tell our CFO that we need to do something that’s going to break the bank.”

Education is key

Keeping employees informed and up to date on new threats is as essential as requiring compliance with corporate best-practices policies. With some corporations now requiring that employees sign a document to acknowledge receipt of corporate security guidelines, accountability for unawareness or careless behavior is growing in popularity.

At Owens Corning, “We put out a lot of communications about recent virus attacks and what’s going on. We talk about what we’ve done inside our company, and then we’ll have a few things that we recommend them to do at home,” Kosanka said.

IBM’s Cianci offered this example: “We have a home page that we run through the corporation. We highlight security, and we do a direct link to our security portal. Any type of virus or worm or anything, you know the first thing to do is hit here. It will tell you exactly what’s going on. From an education point of view . . . we have a corporate instruction that goes out to every employee, and it’s line management’s responsibility to ensure guidance. Then there are audit trails to see that gets implemented worldwide.”

Hasbro has a similar approach, Schwinn said. “Every employee annually signs a set of security guidelines. [What] we’re seeing now is mass e-mail about a problem . . . with instructions. We don’t want to wait for them to go to the Internet. We want them to know about it.”

At the end of the day, the executives agreed that corporations’ security needs will continue to grow but must be implemented in a manner that does not impede core business activities.

Each participant came away with specific areas on which they planned to focus. “I guess the thing I’m left with is thinking about how we could improve the communication that we make as an IT group to our user base,” Hasbro’s Elliott said.

Added Staples’ Ward, “A key take away with me is the whole issue of we really have a major new responsibility I think in terms of educating the business about risk.”

And Peter Johnson, CIO of Dartmouth-Hitchcock Medical Center, summed up the day’s activities this way: “I was comforted that we all had the same problems. It’s a little bit of personal therapy.”