Most enterprise CIO's do not know how effective their data center security controls are, according to the latest Forrester study titled The Value of Corporate Secrets (.pdf). Most respondents to the research firm's survey, commissioned by EMC and Microsoft, were overconfident about the effectiveness of all of their security controls.
The data center security controls include data loss prevention (DLP) software, access-control remediation, data base monitoring, data base encryption and security information management. In addition to data center controls, researchers came to the same conclusion for endpoint security controls (disk encryption, device-wipe software, etc.) and network controls (DLP software, email encryption software).
Most respondents to the survey rated almost all of their security controls as highly effective and said they knew the paths that their most sensitive information traveled. "Most enterprises do not actually know whether their data security programs work or not, other than by raw incident counting," the report concluded. "Even then, an enterprise with a high number of incidents is still likely to imagine that itsprograms are 'very effective.'"
Additionally, Forrester found that high-value firms, who on average have 60 percent more relationships with outside parties than low-value firms, also had more data center, process, endpoint and network controls deployed. These firms suffered four times the number of security incidents suffered by low-value organizations. If employee-related incidents were excluded from the ratio, high-value enterprises suffered six times the amount of outsider incidents reported by low-value firms.
"The more third-party connections an enterprise has, the more incidents it will have that come from outsiders," the report read.
The study defined high-volume companies as those that manage information that is worth $4.8 million, including $3.1 million in secrets and $1.6 million in toxic data. Low-value firms are those whose information assets are worth $243,000.
Forrester surveyed more than 300 organizations in North America, Europe and Australia when conducting the study.
Forrester's recommendations for future action:
