Zibb
Subscribe to Control Engineering
FirstLight
Email
Print
Reprint
Learn RSS

Security: Are you spending enough?

Dennis Brandl, BR&L Consulting -- Control Engineering, 11/1/2004

One problem with writing about network and computer security is the speed at which the threat changes. In the few weeks that separate my writing of this article and its appearance in print, there will probably be another large cyber attack and multiple stories about how companies are not doing enough to ensure computer security.

To appreciate the increased emphasis now being placed on computer and network security by companies of all sizes, consider these attack facts from SecurityStats.com: an unprotected server placed on the Internet in mid-2003 was attacked 467 times in the first 24 hours; that same server detected 626 attacks in the three weeks following its first day on the Internet; the SQL Slammer worm required only 10 minutes to spread worldwide, doubling in size every 8.5 seconds; remediation costs of the MS Blaster worm were estimated at nearly $500,000 per company, with large companies reporting losses in the millions; at its peak, one in 12 e-mail messages on the Internet were sent by the MyDoom virus; PC viruses cost businesses an estimated $55 billion dollars in 2003.

Keep 'em separated

Usually a company's firewalls and security devices protect the corporate intranet and the operations and automation networks. However, it is still advisable to separate operations and automation networks from corporate intranet using firewalls, VLANs, or physical separation. Automation and operation systems are often mission-critical systems. This means they must remain operational for production to continue. Unfortunately, these systems often are not running current virus protection and current patches, but not due to a lack of effort on the part of manufacturers. In 2003, Microsoft released 51 security advisories across all products—about one patch per week—to help counter the new viruses and worms that are released daily by cyber-vandals.

All of this begs the question: What is the right amount to spend on security and related network infrastructure?

Hardware, software, personnel

According to several public surveys, security hardware, software, and personnel seem to comprise about 4% of IT budgets. Some industries, such as financial organizations and universities with mission-critical IT infrastructures, spend more—averaging about 7% of their IT budget (up to 20% in a few cases). An additional 7% is being spent on network infrastructure, with some of that money earmarked for security issues. META Group (an IT analyst organization) estimates the average security investment will peak at 8% to 12% of IT budgets in the United States by 2006. The security portion of IT budgets is split about one-third each on security hardware (firewalls, intrusion detection systems, e-mail scanners, etc.), security software, and security personnel.

Based on industry standards for mission critical applications, the average manufacturing IT organization should be spending about 5% to 10% of its manufacturing IT budget on security. This is a comparatively small percentage and easy to forget or ignore in capital projects and yearly budgets. However, security costs must now be figured into expenses, much as insurance is now, because these costs represent a pure cost with no tangible return until they are needed. Then it definitely becomes money well spent.

For further reading on this topic, see the NIST "Introduction to Computer Security" handbook at http://csrc.nist.gov/publications/nistpubs/800-12/handbook.pdf.


Author Information
Dennis Brandl is the president of BR&L Consulting, a consulting firm focusing on manufacturing IT solutions, based in Cary, N.C. dbrandl@brlconsulting.com

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Related Content

Related Content

 

By This Author

Sponsored Links

 

Advertisement
SPONSORED LINKS

More Content

  • Blogs
  • Discussions
  • Webcasts
  • Podcasts
  • Videos

Blogs

  • David Chappell
    Standard profits: Make2Pack and ISA88

    January 8, 2009
    Make2Pack ISA88 Part 5 meeting calendar for 2009, as of Jan. 8
    Wow! Another year of Make2Pack ISA88 Part 5 effort is behind us, and a brand new one is coming at us like a freight train. As this year un......
    More
  • Peter Welander
    Pillar to Post: Peter Welander's Blog

    January 7, 2009
    Is nothing growing in manufacturing?
    Manufacturing is down. You might have already heard something to this effect, but the extent of the economic downturn in December may surprise you.......
    More
  • View All BlogsRSS

Webcasts

Engineering-driven Ethernet
This Control Engineering Roundtable Webcast will address the engineering issues you should be aware of when exploring the adoption of Ethernet or when looking to expand its use in your facility.

Bridging gaps with wireless
Discover how you can create stronger, flexible and cost-effective wireless connections for your entire plant. Register today!

View All Webcasts

Podcasts

How much does biofuel production affect food markets? Can corn-based ethanol break the grip of oil? Agribusiness economist Dr. T. Randall Fortenbery explains some of the complex relationships of energy production to Peter Welander.
Economics of Biofuels
How much does biofuel production affect food markets? Can corn-based ethanol break the grip of oil? Agribusiness economist Dr. T. Randall Fortenbery explains some of the complex relationships of energy production to Peter Welander. Hear It Now

View All Podcasts Subscribe Now to Process Control & Instrumentation and never miss an episode
Advertisements





NEWSLETTERS

Get engineering industry news, trends, and business-critical information delivered directly to your inbox!

Click on a title below to learn more.

Weekly News (Weekly)
Process Instrumentation & Sensors (Monthly)
System Integration Monthly (Monthly)
Process & Advanced Control (Monthly)
Machine Control (Monthly)
Information Control (Monthly)
Automation Control (Monthly)
Product Review (Monthly)
Sustainable Engineering (Monthly)
Simplified Safety
Fieldbus Facts
PROFInews North American Edition
About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Useful Sites   |   FREE Subscription   |   RSS
© 2009 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites