Windows is the 'biggest beta test in history' - Gartner

Less is more


Spending more on security doesn't necessarily make you more secure, Gartner warned yesterday.

The analyst firm forecasts that information security spending will drop from an average six-to-nine per cent of IT budgets to between four and five per cent as organisations improve security management and efficiency. Victor Wheatman, Gartner security veep, told delegates at the IT Security Summit in London that the most secure organisations spend less than the average and that the lowest spending organisations are the most secure. The businesses can safely reduce the share of security in their overall IT budget to three or four per cent by 2006, he said.

The idea that the most secure organisations spend the most on security was among a number of myths debunked by Wheatman during a keynote before approximately 700 delegates at the Gartner IT security Summit yesterday. He also attacked the popular misconception that "software has to have flaws". Wheatman said this is true only if enterprises continue to buy flawed software, and he singled Microsoft out for particular criticism.

He described Windows as “the biggest beta test in history" and warned warned IT security pros not to expect too much from Microsoft’s vaunted Trustworthy Computing initiative. "Microsoft will try, and there'll be improvement with Longhorn, but it will not solve all your security problems - no matter what the richest man in the world says,” he said. According to Gartner better quality assurance of software is needed before it goes into production. If 50 per cent of vulnerabilities are removed prior to software being put in production then incident response costs would be reduced by 75 per cent, it estimates.

Gartner has identified IT security technologies enterprises will need over the next five years - and other technologies most companies probably won't need. On the enterprise shopping list is host-based intrusion prevention, identity management, 802.1X authentication and gateway spam and AV scanning. Security technologies Gartner reckons most companies can safely do without include personal digital signatures, biometrics, enterprise digital rights management and 500-page security policies. ®

Related stories

Insecurity downtime on the up
'Independent' report used MS-sourced data to trash OSS
Microsoft warns of poisoned picture peril
Investors fret about IT security


Keep Reading

Tech Resources

What WAF is right for you

Applications are architected in many ways, but all need protection from threats. Learn the most important things to consider when choosing a WAF.

Three reasons you need a hybrid multicloud

Businesses need their IT teams to operate applications and data in a hybrid environment spanning on-premises private and public clouds. But this poses many challenges, such as managing complex networking, re-architecting applications for the cloud, and managing multiple infrastructure silos. There is a pressing need for a single platform that addresses these challenges - a hybrid multicloud built for the digital innovation era. Just this Regcast to find out: Why hybrid multicloud is the ideal path to accelerate cloud migration.

Top 20 Private Cloud Questions Answered

Download this asset for straight answers to your top private cloud questions.

How backup modernization changes the ransomware game

If the thrill of backing up your data and wondering if you will ever see it again has worn off, start the new year by getting rid of the lingering pain of legacy backup. Bipul Sinha, CEO of the Cloud Data Management Company, Rubrik, and Miguel Zatarain, Director of Global Infrastructure Technology at PACCAR, Fortune 500 manufacturer of trucks and Rubrik customer, are talking to the Reg’s Tim Phillips about how to eliminate the costly, slow and spotty performance of legacy backup, and how to modernize your implementation in 2021 to make your business more resilient.

Biting the hand that feeds IT © 1998–2021