Share

Top 5 Stories

News

Half of oil and gas companies have no information security strategy in place

27 July 2011

Only half of oil and gas companies have put in place a strategy to address information security threats, according to a survey of oil and gas IT executives by IDC Energy Insights.

The survey of global IT executives also discovered that oil and gas companies still lag behind other industries in formulating approving, and executing information security policies, as well as getting buy-in from senior management.

"In oil and gas companies, awareness of appropriate security policies and best practices is still not good enough. They need to be better prepared to prevent and manage security breaches. This is not the time to reduce the budget for IT security and compliance", commented Roberta Bigliani, head of Europe, Middle East, and Africa IDC Energy Insights.

Of the top three information security threats perceived by oil and gas companies, the greatest is state or industrial espionage, followed by employee error or accidental loss of sensitive information, and vulnerabilities owing to insecure code, the survey found.

In addition, 55% of survey respondents indicated an expected increase in their information security budget over the next 12 months. Only 10% of the respondents indicated that they are using regulatory compliance as a requirement to justify budgets. In fact, almost 25% of respondents said that the regulatory environment was a barrier to ensuring information security

More than 31% of US respondents stated that information security was a top IT initiative at their company in 2011, but only 12% of the respondents indicated that they are actually making investments to improve information security and mitigate risk.

"Software spending is increasing for client security solutions such as antivirus and antimalware. Investment in security appliance solutions such as firewalls and intrusion prevention remains low this year, as just 10% of the survey respondents indicate investing in them", concluded Usman Sindhu, senior research analyst at IDC Energy Insights.

This article is featured in:
Business Continuity and Disaster Recovery  • Compliance and Policy  • Internet and Network Security • Malware and Hardware Security

 

Comments

MrEthiopian says:

27 July 2011
They don’t care or need to care, look what BP did to America and it’s not even an American company, when a company can cause such egregious felonious actions like in the case of BP destroying the ocean and the way of life for so many people. Self-police the entire cleanup effort and not allow valid journalists or scientists document their effort and in the end simply walk away and say that you’re done when in actuality we will be cleaning this mess up for millennia to come.

Note: The majority of comments posted are created by members of the public. The views expressed are theirs and unless specifically stated are not those Elsevier Ltd. We are not responsible for any content posted by members of the public or content of any third party sites that are accessible through this site. Any links to third party websites from this website do not amount to any endorsement of that site by the Elsevier Ltd and any use of that site by you is at your own risk. For further information, please refer to our Terms & Conditions.

Comment on this article

You must be registered and logged in to leave a comment about this article.