Advertisement
Promo

Security threats Toolkit

'Microsoft will not completely protect you' says Gartner

Dan Ilet ZDNet.co.uk

Published: 20 Sep 2004 12:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

It's official: don't expect Microsoft to completely protect your network.

"We've all been part of the biggest beta test the world has ever known -- Windows. Microsoft will not solve all of the security problems, no matter what the richest man in the world says," said Gartner vice president Victor Wheatman in a keynote speech at Gartner's IT Security Summit on Monday.

Wheatman kicked off the conference saying that removing faulty software during operation was costing firms up to 5 percent more than finding flaws during quality assurance tests.

"One of the problems is that there are maybe only 500 software engineers in the world who can burrow around in that code to find the problem. That's something the industry needs to look at," he said.

But Wheatman had some good news for users -- he said that the level of spam on the network was dropping because spam technology was improving.

"Spam [on the network] seems to be in decline. The level of spam has dropped to a point where we can actually do our work now," he said.

Wheatman also used his speech to attack the media for what he said was hyping-up the threat of cyberattacks.

"People who hype up cyberterrorism, spam and phishing are creating more fear, uncertainty and doubt than is necessary," he said.

Board-level members will also require more information on how security is benefiting the firm, he said: "We will see more pressure put on IT security. Boards are going to want to see more information on securing the network to demonstrate the financial value of security."

Wheatman also called for security specialists to ditch their intrusion detection systems in favour of intrusion prevention technologies. He said that other technologies that firms could drop included biometrics, digital rights management and personal digital signatures. Instead they should shift investment into host-based intrusion prevention systems, vulnerability management and advanced encryption protocols.

More than 700 security professionals gathered at the conference in London today.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
68 out of 136 people found this useful


Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters