IT Security in the SMB - Call for input
One of the catch phrases when discussing IT Security is the principle that there is no "silver bullet". In order words, there is no one thing or solution that will solve all of your IT security problems. With that in mind, I would like to turn the focus on the small to medium business (SMB). Over the past few years, I have observed a lot of development being done for the SMB markets that work to integrate as many different layers of IT security into one product as possible.
At the same time, IT security has become integrated into a business must do rather than a business should do thanks for IT security regulations and a change in thinking for business leaders that have learned over time that IT security can be a business decision driven by ROI.
Given these two primary factors I have observed impacting this market, my concern is that while SMB business leaders are now more aware of IT security as a necessity, how many of them are falling into the old trap of relying on a single purchase to satisfy all of their needs? Even though multiple function devices are improving, there is still no silver bullet. Or has the industry made progress in educating these business leaders that security is a journey, not a destination.
I am requesting feedback from anyone who works with these types of business and can provide their thoughts from the field.
I will be looking at all of the feedback I get and posting a follow-up article on a future shift.
Comments
When I started their idea of security was a router, and the first device I setup was a ipchains firewall.
As we have grown, I have been able to, little by little add more secure products/hardware. But at the same time have had to give up areas of past control to deal with the growth. I was not security minded as these things were deligated out and now my biggest problems are now the people who are incharge of things like AD, or the ERP system.
And our latest IT director wants one vender to beat up on, but 3 quotes every time we do something.
As of late I have transisioned my job in to security (Both physical and Network) and have started sending both the CIO IT Director and the AD administrator stories I find on the web from around the world. This seems to have garnered their attentions and we are starting to review security and DR. It has taken a long time but I think once you can show that real threats exiest, which we all know they do, they people in charge will make the right choices.
But for those of you out there who have managers who read the industry mag, and that is how they make there selections, all you can do is prepare for the worst case, and once you clean up the mess that will get made, say to the management, "I TOLD YOU SO!, Now are you going to listen?"
Good luck to all
Travis
Feb 3rd 2008
1 decade ago
$.02 deposited.
Greg
Feb 3rd 2008
1 decade ago