You are here: silicon.com > Management > SME Director

SME Director

Staff blamed for SME security breaches

But is it a matter of policy?

Tags: employee, it manager, breach, security

By Tim Ferguson

Published: 23 August 2007 10:30 BST

IT managers in small and medium sized businesses (SMEs) blame their fellow workers for online security breaches - despite the fact many SMEs still don't enforce web usage policies.

More than a quarter of European SME IT managers said they believe company employees are responsible for security problems, according to research commissioned by security software company Websense.

The most frustrating problem for IT managers is employee behaviour (cited by nearly a third of managers), followed by security not being high enough on the corporate agenda and then budget constraints.

silicon.com's Full Disclosure campaign - what we are asking for...

silicon.com wants the government to review its data protection legislation and improve the reporting of information security breaches in the public and private sectors.

We are calling for greater public debate and for the government to consider legislation that would require organisations that suffer information security breaches to alert their customers if there is a chance the breach has put individuals' sensitive personal data at risk.

We want to hear your views about this campaign and the issues it raises. Make your voice heard by leaving a Reader Comment below, emailing us at editorial@silicon.com or signing the 10 Downing Street e-petition.

The survey found nearly a third of employees said they need to access sites known to present a high security risk, such as peer-to-peer services and free software download sites.

The extent to which workers use the web is highlighted by the finding that European employees spend an average of around two hours per day online at work, with around half an hour of that spent browsing non-work related sites.

But suspicious IT managers believe the time spent on non-work related sites is actually closer to 48 minutes - or the equivalent of four hours per week.

The survey also reveals 23 per cent of SMEs have web security policies but don't require employees to sign up to them. Another 16 per cent have no web usage policy at all, preferring to trust employees to not put them at risk.

The SMB State of Security survey covered 375 IT managers and 375 employees from companies of between 100 and 250 users in France, Germany, Italy, the Netherlands and the UK.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Information Security Analyst

This role will be well suited to a security practitioner with strong skills in information security and business continuity risk and ...

INFORMATION SECURITY OFFICER

Developing and documenting BS7799 compliant Information Security policies and procedures. INFORMATION SECURITY OFFICER 32,436 - 39,258 PER ANNUM ...

Information Security Officer

Information Security Issues ISEB certification in (Information Security Management) and (Data Protection) Certification in 1SO 27001 (Risk Assessment ...

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.





Quick Sitemap Links: