Survey: Gap Remains Between IT Security Issues And Deployed Solutions

CDW Corp. recently released the CDW User-Proof IT Security Report, which reveals a disparity between the most common IT security headaches and businesses’ deployment of solutions that could relieve them.

Survey respondents said their most common problems stem from employees using the Internet inappropriately, using unapproved software, and circumventing security infrastructure and policies. However, the study found companies lagged in their use of tools such as Internet content filtering or network auditing and visibility systems, which would help IT management spot and sometimes avoid such risky behavior by network users.

Specific findings of CDW’s User-Proof IT Security Report include:

  • Inappropriate use of the Internet on company networks is the top IT security headache, but just 56 percent of companies have Internet content filtering and blocking solutions in place
  • Installation and use of unauthorized software programs is a top challenge, but just 40 percent of respondents note that they employ network auditing and visibility systems
  • IT professionals whose organizations employ content monitoring and filtering, SSL protection, mail gateway security and similar measures to address common headaches give their network users higher grades for overall IT security compliance

CDW surveyed IT professionals at companies with more than 100 employees, focusing exclusively on those who said their organizations have written IT security policies and procedures. The survey asked respondents to grade their IT network users as a group on their understanding of and compliance with their IT security policies, and then asked in-depth questions regarding what security measures their companies employ and how IT security solutions could be improved to increase user compliance.

Responding IT professionals said their IT security systems are easy to use, but also reported much room for improvement in end-user understanding and compliance with security policies and procedures.

Seventy-seven percent of IT professionals said that their IT security systems are very easy or somewhat easy to use, but just 23 percent gave their users an ‘A’ on compliance with IT security policies, procedures and required practices. Asked to assess available security solutions, IT professionals wanted vendors to provide still more user-friendly and easier-to-manage solutions that require less IT staff intervention.

“Clearly, IT departments -- and IT security managers in particular -- are some of the busiest people in the business world today, and they spend so much time responding to client department needs that they don’t always have time or resources to address security priorities,” said Grimsley. “Outside resources appear to play an increasingly important role in IT security, and having a trusted advisor to lean on for information and counsel may help IT professionals make better decisions more quickly.”

CDW’s national online survey, taken during March 2008, collected responses from 304 IT professionals who said their companies have written IT security policies and procedures. Thirty-nine percent of the participants were from companies with 101-500 employees, and 61 percent were from companies with more than 500 employees. The margin of error for the study is ±5.6 percent at a 95 percent confidence level.

For the complete survey, visit http://www.cdw.com/userproofsecurity.

Featured

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

  • ASIS International Introduces New ANSI-Approved Investigations Standard

    • Guard Services
  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.