UK firms treble IT security spend

Government survey unveiled at Infosec reveals UK firms now committing 7 per cent of IT budget to security, up from 2 per cent in 2002

By Sam Trendall

More from this author

22 Apr 2008

Be the first to comment

  • Digg
  • Tweet

A survey commissioned by the Department for Business, Enterprise and Regulatory Reform (BERR) has revealed that UK companies are spending three times as much of their IT budget on security as they were six years ago.

The 2008 Information Security Breaches Survey was carried out by a consortium led by professional services company PricewaterhouseCoopers and the results were revealed at the Infosecurity Europe event in London this week. The survey showed that the average UK firm spends 7 per cent of its IT budget on security, compared to 2 per cent in 2002.

During that time the total cost of security breaches to UK firms has fallen 35 per cent, although a quarter of businesses reported a serious security breach in the last two years. The survey demonstrates that companies are becoming more security savvy, demonstrated by the more than 90 per cent that back up critical systems, have implemented spam filters, firewalls, anti-virus and anti-spyware software and have encrypted wireless network transmissions.

Further reading

55 per cent of firms now have a documented security policy, compared to 27 per cent in 2002, while 40 per cent give their staff ongoing security training, double the amount that were doing so in 2002.

But the survey also reveals many companies have a worryingly lackadaisical approach to other aspects of security. 84 per cent do not check to ascertain whether outgoing email contains confidential information and 78 per cent that had been victims of computer theft did not encrypt hard discs. 72 per cent do nothing to prevent data leaving on portable memory devices, 52 per cent do not carry out a formal security risk assessment and 48 per cent have not tested their disaster recovery plans in the last year.

35 per cent exercise no controls on their staff using instant messaging, 21 per cent spend under one per cent of their IT budget on security and 10 per cent of websites accepting payment details do not encrypt them. Despite the drop in the cost of security breaches to the UK economy, only 17 per cent of businesses expected the numbers of incidents to fall next year.

Parliamentary under secretary of state for BERR Shriti Vadera said: "New technology is a key source of productivity gains, but without adequate investment in security defences these gains can be undermined by IT security breaches. The survey shows increasing understanding by business of the opportunities and threats, but challenges remain."

Chris Potter, partner at PricewaterhouseCoopers, said: "There are still some fundamental contradictions. Some 79 per cent of businesses believe they have a clear understanding of the security risks they face, but only 48 per cent formally assess those risks. Also, 88 per cent are confident that they have caught all significant security breaches, but only 56 per cent have procedures to log and respond to incidents. The survey also shows 71 per cent have procedures to comply with the Data Protection Act, but only 8 per cent encrypt laptop hard drives. Businesses all need to ensure that their defences are sound if they want to continue to enjoy the benefits that technology brings.”

display:none
Loading
We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions

Your comment will be moderated before publication.

Will Apple's attitude to the channel change in 2012?

51%

22%

26%

1%

CRN Partner Connect 2012

CRN Partner Connect logo

CRN's premier networking event is back on 17 May at the Ricoh Arena

Date: Thu 17 May 2012

CRN Fight Night 2012

One of the fights from CRN Fight Night 2010

Channel fighters preparing to square up once more on 24 May

Date: Thu 24 May 2012

Sign up for our range of FREE newsletters:

Submit your email address and we'll send a link to a personal newsletter control panel

fragment image

The mobile enterprise: Secure the data, not the device

The proliferation of endpoint devices within the enterprise has highlighted the shortcomings of one of the traditional approaches to data security

fragment image

Measuring the ROI of Google Apps

This Forrester report compares the costs and benefits of legacy email and productivity software with Google Apps


Dave the dealer blog

Dave the dealer

Clocking off

Dave discovers that rozzers are seemingly living in the technology dark ages

View from the channel

Views from the Channel

Departing CEO has done Dixons a service

Mark Needham, founder of distributor Widget, argues that John Browett leaves for Apple with Dixons in better shape than when he arrived

To send to more than one email address, simply separate each address with a comma.