Information security no longer remains a concern just for CIOs and technology practitioners as organizations slowly start to realize it's importance to the business itself. But can this be called growth or rather how significant is this growth when measured in terms of global standards?
[caption id="attachment_1470395" align="alignleft" width="150"]
Scott Robertson Vice President-Asia Pacific at WatchGuard[/caption]
[caption id="attachment_1471986" align="alignleft" width="131"]
Govind Rammurthy ,MicroWorld Software Services Pvt. Ltd.[/caption]
[caption id="attachment_1290511" align="alignleft" width="150"]
Rajesh MauryaCountry Manager India & SAARC, Fortinet[/caption] [caption id="attachment_1470099" align="alignleft" width="150"]
Sunil Sharma VP Sales & Operations, India & SAARC, Cyberoam[/caption]
IT security is no longer an issue related to only IT and security professionals. It has now become a persistent business risk. According to Gartner, Security spending will continue to grow in 2015 with revenue projected to reach $1.06 billion. As cyber-crime incidents continue to haunt businesses and government agencies, safeguarding data and networks has become a challenge to them. In addition to the traditional sectors like banking, telecom, Financial Services and ITeS, Healthcare, Pharmaceutical, Utilities, oil and gas and the manufacturing sectors are also deploying enough resources and investing on Information Security as per reports.
"The security spends of Service Providers according to a Frost forecast will increase by 25% this year and touch US$ 70 million. While consulting, implementation, support and managed security services will comprise 55% of the market, Manufacturing, Education, Healthcare & Retail along with others will contribute to 30% of the market spend," says Rajesh Maurya, Country Manager India & SAARC, Fortinet.
Market on a Growth Trail….
Over the years the Information Security market in India has seen an eminent rise. India is among the world's top-5 vulnerable country in terms of data breach threats from malicious cyber activities. With the rapid development of newer technologies relevant for corporate network expansion and data transfer, the information security landscape needs to transform itself in order to counter a new breed of online malicious entities being identified in India as well as globally.
Although it has been gradual, the pace of Information Security is picking up quite well. Be it any business segment or vertical, looking at the current scenario of IT security landscape, it has become mandatory for all to ensure the security of information assets. "We observe growing awareness on security as businesses realize how it ties with IT and business goals. There is a clear acknowledgement for the changing role of security and how it functions as a catalytic force to turn disruptive into productive, helping businesses and CXOs embrace IT without any issues," remarks Sunil Sharma, VP Sales & Operations, India & SAARC, Cyberoam.
IT is the backbone of every business today. One has to make sure that their business is making the right use of IT to enable every business process to function optimally and that everything works smoothly with no down time and no security breaches or delays. “Information is a crucial element as we deal with it on multiple platforms daily. Our core focus is securing data available on multiple platforms. It implies to securing all those multiple platforms as well. The need for information security is increasing globally and it’s not just in pockets or in specific industries,†opine Kailash Katkar, CEO & Founder – Quick Heal.
[caption id="attachment_810637" align="alignleft" width="150"]
Kailash Katkar CEO & Founder – Quick Heal[/caption]
[caption id="attachment_180167" align="alignleft" width="150"]
Karthik Shahani Regional Director, RSA - India And SAARC[/caption]
[caption id="attachment_60372" align="alignleft" width="120"]
S. Sriram CEO at iValue InfoSolutions[/caption]
[caption id="attachment_1410379" align="alignleft" width="144"]
Altaf Halde Managing Director, Kaspersky Lab -South Asia[/caption]
"In the information age, the real assets of any business are its IP and business differentiators. For business to grow profitably, these business differentiators need to be managed from internal and external threats. Compliance is another critical business need as India is a leading ITeS provider to the rest of the world. Hence effective management of "Business assets and differentiators" is critical to ensure profitable growth of companies across size and vertical,†informs S. Sriram, CEO at iValue InfoSolutions.
As is seen, the nature of attacks is swiftly becoming more targeted towards the individual, which eventually is becoming more personalised. Further, security today is not just about tackling a breach after it has already happened, but preventing an attack or breach before it actually happens. “It is time that an organization treats information security as a business function and not just another IT practice. The prime focus of CIOs and CTOs has to now reach the purview of business leaders, including the C-suite executives such as the CEO and the MD. Such an attack can bring down the whole business unit thus causing huge losses to the companies,†warns Ambarish Deshpande, Managing Director-India, Blue Coat Systems.
Dan Dinnar, Vice President, Asia Pacific, CyberArk Software, Ltd agrees that in recent years businesses have been facing more sophisticated, advanced targeted attacks, especially organizations in the critical infrastructure, or related, market. “Even though investments have been made in information security, they have primarily been reflective of compliance mandates. In today’s market, there is a pressing need to have dynamic security practices in place which can help protect, detect, monitor and respond to potential threats,†he opines.
[caption id="attachment_780414" align="alignleft" width="150"]
Ambarish Deshpande Managing Director-India, Blue Coat Systems[/caption]
[caption id="attachment_1472426" align="alignleft" width="150"]
Pankaj Jain Director at ESET India[/caption]
[caption id="attachment_1472427" align="alignleft" width="150"]
Sudeep Charles Product Marketing Manager – Asia Pacific & Japan, Akamai Technologies[/caption]
[caption id="attachment_1472428" align="alignleft" width="150"]
Ashesh Thanawala Sales Director – India & SAARC, SafeNet[/caption]
The Growth Propellants…
Just a few years ago, security had perhaps been a tiny spot on the overall agenda of CXOs or IT managers. But now it is not. “On one hand where technological advancements is leading to digitization, on the other hand technology is also being used as a lethal force, with hackers and cyber criminals finding the vulnerable areas, launching evolved targeted attacks and writing more skillful malware code, which is collectively propelling the growth of information security,†replies Sunil.
Sophisticated threats like Advanced Persistent Threats (APTs) have grown in both severity and volume in the last few years and this is further driving the need for businesses to implement strong defense mechanism. According to Pankaj Jain, Director at ESET India, increased Internet penetration & digitalization are propelling the growth of Information security segment, though ‘Computing everywhere’ & ‘Internet of things’ with huge challenges of securing the network of devices that interconnects information, operations as well as technologies, also play a crucial role in its growth. “Social media promotions and interconnections with other sites provide new threat vectors for criminals to exploit. Adoption of Software as a Service (SaaS)-based security solutions, threats like Distributed Denial of Services (DDoS) and APTs also are the factors in driving the Information Security System,†he says.
The availability of affordable mobile devices like tablets and smartphones has further boosted the growth of the Information security segment. This, coupled with a large number of enterprises adopting an online business model has led to its growth in India. “Delivery models are significantly impacting a number of markets in India. This is resulting in the growth of cloud-based security services, which are transforming the way security is provided and utilized by customers. Organizations are making the change from deploying on-premises products to cloud-based services,†views Sudeep Charles, Product Marketing Manager – Asia Pacific & Japan, Akamai Technologies.
The last few years have witnessed a series of high-profile cyber attacks which has prompted many businesses around the world to beef up their protection, increasing their budgets and expediting deployment of security projects. Interestingly, Information security has taken center stage for many of the organisations in India and this focus will continue to grow. Organizations in India that traditionally did not have a focus on security technologies are now beginning to realize the implications that a weak information security and risk posture can have on their businesses. “The good part is that until now, Indian organizations were having only limited focus on IT security. However now, as the awareness about IT security is increasing, we see them moving towards comprehensive cyber-risk management. In addition, there are many MNCs operating in India that are working towards aligning their IT security strategies along with the NIST Cyber Security Framework which has been advanced by the US government,†remarks Govind Rammurthy, MD & CEO at eScan.
Karthik Shahani, Regional Director, RSA - India and SAARC is of the same view. “This combined with regulations /guidelines laid by industry bodies in some verticals, businesses moving online for growth, mobile access to business applications, consumers adopting mobile platforms etc. are some other factors which has led to the growth in the Information Security market in India,†he said.
[caption id="attachment_1472429" align="alignleft" width="150"]
Dan DinnarVice President, Asia Pacific, CyberArk Software, Ltd.[/caption] [caption id="attachment_1472430" align="alignleft" width="150"]
Sonit JainCEO at
GajShield[/caption] Although organizations have raised the bar in security, their adversaries have made sure they are a step ahead. A recent survey shows a 98 percent jump in the number of incidents reported this year and average financial losses have gone up by 26 percent in India compared to the global average of 18 percent. “Indian companies have been focusing on compliance-based and perimeter-oriented security strategies. While they have proved to be useful in the past, these traditional strategies alone will not be able to meet challenges posed by adversaries leveraging the threats and technologies of tomorrow,†Sonit Jain, CEO at GajShield. Says Ambarish, “Advanced threats cannot be blocked by merely adding additional security protection. While most organisations have implemented many security applications that provide them with a sense of security, cyber criminals keep finding newer ways to get within a secured system. Existing technologies are equipped to block known threats; however it is impossible to block a threat that is targeted and persistent.†Going ahead… The 2014 SafeNet Data Security Confidence Index found that nearly three-quarters (74 percent) of IT decision-makers believe that their organization’s firewall is effective at keeping out unauthorized users. Yet, nearly half (44 percent) admit that their organization’s firewall has been breached or do not know if it has been breached. “The survey results illustrate that despite the increasing number of network breaches and data record losses, businesses are continuing to invest more of their IT budgets in perimeter security and breach prevention technologies versus defense-in-depth strategies that include strong multi-factor authentication and data encryption,†says Ashesh Thanawala, Sales Director – India & SAARC, SafeNet. Although the growth in Information security has been significant, India lags behind. As compared to global standards, there are many Indian organizations that still continue to be unaware of cyber-attacks and not keen on reporting detected incidents. Scott Robertson, Vice President-Asia Pacific at WatchGuard, cites, “According to the Ernst and Young Global Information Security Survey, organizations in India lack the agility and the budget to be able to detect possible security threats and prepare for the same. A lot of factors contribute to this like careless employees, out of date information security controls and unauthorized access, only to name a few. Moreover the Indian firms have reduced the assigned budget for Information Security by 17% in 2014, according to a survey done by PWC.†Frankly, there is no more time to wait on the issue of cybersecurity. Government agencies and corporations alike must become both educated and absolutely determined to stop cybercrime now. 2015 needs to be a wakeup call for businesses and individuals alike. Neither can afford mediocre approaches to security and customers. Organizations must have the right plans and the right technologies in place to deal with the threats we’ve seen do so much damage in in 2014. As put by Altaf Halde, Managing Director, Kaspersky Lab -South Asia, no matter what defense you have in place, prevention is always better than cure. “There’s a lot to think about, and for your security policies to be effective they need to bring every user’s devices, applications – and even their behaviors – under control. More than that, they must be realistic. And by making sure that all employees are taking basic steps to protect themselves, you can go a long way to reducing the risk of a security breach. Something as simple as strong, unique passwords can make a huge difference,†he says. How to Stay Digitally Safe? Over the years the focus has largely been on preventing security threats rather than detecting one. But at the same time as the threats continue to increase; organizations today are embracing stronger security systems, as they have come to understand the need to better protect their networks and data. Some of them are – • Apart from deploying defense mechanisms organizations are slowly starting to proactively protect the sensitive data by applying uniform data protection policies across the networks and the servers throughout the organization. Various protective measures such as patch management, password settings, configuration of the firewall and the servers, are helping firms to protect sensitive information • Solutions such as data loss management and security event management help in preventing data breaches during outbound transmission. Organizations that have a dedicated security team are constantly reducing the risk of security breach by increasing their knowledge of threats making them less vulnerable to security breach • Some organizations also go to the extent of implementing detection / prevention systems which would detect and prevent attacks in real-time. However, they have to be proactively monitored and users too have to be proactive in their approach • Few of the customers are also rapidly incorporating Advanced Threat Protection technologies into their network security infrastructure • Midsized business segment are seen increasingly deploying defenses in the cloud. This approach provides scale against fairly large attacks and protects businesses from threats before they reach the datacenter Besides these security systems in place, there are also various safety measures that needs to be implemented at a personal level to keep the network and data safe from being getting compromised - • Mobile should be a central part of an overall IT security policy. By being proactive, one can help prevent data loss from sophisticated threats such as malware, and simple mishaps like losing a device • Just as URLs, files and attachments can be used to transmit malware, so can physical devices.. Even if its company branded, that doesn’t necessarily mean its safe. Any device that’s been in contact with an unknown network could be infected • It’s important for employees to understand that, even if their browsing is personal, the risks can affect the entire company. By encouraging the right behaviours, IT manager can implement a policy that keeps the network and data safe without impinging on the quality of employees’ work life




