Survey: Employee Use of Social Media Heightens Security Concerns

According to findings from the eighth annual "What Keeps Network Administrators Up At Night" survey commissioned by VanDyke Software and executed by Amplitude Research, increased complexities such as the use of social media and smartphones by employees are keeping network and systems administrators at enterprises busy — although more than half feel sufficiently budgeted and/or staffed to support current information security needs.

The proportion of network administrators "sleeping like a baby" reached a new low in 2011. When network administrators were asked, "What keeps you up at night?" 41 percent selected a "security breach to your network." When the same question was asked in each of seven prior years, between 27 and 39 percent had indicated that worries about a security breach to their network was "keeping them up at night." Meanwhile, according to the 2011 survey findings, "users" were keeping 40 percent of network administrators awake at night. In seven prior years, between 28 and 38 percent had selected "your users" when asked "What keeps you up at night?"

Smartphones and Social Media are Added Complexities to Manage

Approximately four-in-ten (42 percent) network administrators considered managing the security of employee smartphones to be "very important" or "extremely important" as compared to other security threats facing their organization. Only about half (49 percent) of network administrators were satisfied with the security of handheld devices (e.g., Palm, BlackBerry) at their organization — down significantly from 57 percent in 2010.

Approximately four-in-ten (42 percent) were "moderately concerned" to "extremely concerned" about the security threat associated with employee use of social media. The proportion "moderately concerned" to "extremely concerned" was similar in 2010 (40 percent). When network administrators were asked to explain in their own words what concerns them most about employee use of social media at their organization, the most common themes were viruses (19 percent), data/information leaks (19 percent), intrusion risk (19 percent), users not being careful (9 percent), Trojan horses/other malware (9 percent) and concerns about risks to privacy/user information (6 percent). In addition to concerns related to security, 21 percent complained about employees wasting time on social media instead of being productive at work.

Cloud Computing Adoption on the Rise

The adoption of cloud computing rose significantly in 2011 — 22 percent compared to 15 percent in 2010. Among those who have not already adopted cloud computing, many are currently considering it. In fact, those who have not adopted and are not considering cloud computing are in the minority, with the proportion in this group declining significantly from 38 percent in 2010 to 27 percent in 2011. However, survey findings showed that less than half of those who have adopted cloud computing rated it "very secure." An even smaller proportion of those who have not yet adopted cloud computing consider it "very secure." The findings signaled there is room to increase the proportion willing to consider cloud computing very secure, even though network administrators often consider cloud computing to be "somewhat" secure.

IT Security Budgets and Staffing Often Viewed as Adequate to Meet Needs

The proportion seeing any decrease in their IT security budget went from 33 percent in 2009 to 20 percent in 2010 to 15 percent in 2011. In contrast, the proportion seeing any increase in their IT security budget went from 15 percent in 2009 to 30 percent in 2010 to 34 percent in 2011. Thus, as of 2011, 34 percent are seeing an increase vs. 15 percent who are seeing a decrease in their IT security budget.

The proportion feeling their organization has budgeted sufficiently to support current information security needs was 58 percent in the 2011 survey. At the same time, though, 63 percent felt their organization is sufficiently staffed to support current information security needs.

Moreover, the proportion seeing an increase in the size of their IT security staff for 2011 was similar to the proportion seeing a decrease in the size of their IT security staff (15 vs. 14 percent, respectively).

Possible Link Between Government Spending and Enterprise IT Security Budgets

Current spending patterns by state and local governments appear to have impacted some organizations, with those who noticed reduced spending more likely to report reductions in IT security staffing, overall IT budgets, and IT security budgets than those not reporting reduced spending by state and local governments.

Approximately 1/4 (26 percent) of the respondents indicated that they are seeing less spending by state and local governments in areas directly related to their company's business operations, while only 15 percent were seeing more spending. Twenty percent of those who noticed reduced spending by state/local governments were also seeing a decrease in the size of their IT security staff. This was significantly higher than the 11 percent of all other respondents who were seeing a decrease in IT security staff.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3