Advertisement
Promo

Security threats Toolkit

Microsoft security chief attacks government

Andrew Donoghue ZDNet.co.uk

Published: 01 Feb 2006 18:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft UK's chief security advisor Ed Gibson has attacked the government over what he claims is a lack of effective reporting channels for Internet-related crime.

Speaking at the launch of a CBI report into online security for small and medium-sized businesses, Gibson said that while creating documents was all well and good, very few companies had any real notion of who they should report an electronic attack to.

"I bet if I asked anyone in this room, 'Who would you report an electronic crime to in the Police?', no one would know," Gibson said. "We are ignorant of the size of the problem. There is a real lack of meaningful statistics."

Rejecting the offer of a microphone and choosing instead to stride up and down between the panel of experts and the audience of IT and business professionals, Gibson claimed that the government was not doing enough to facilitate the timely reporting of cyber crime.

Gibson said that the decision to roll the National Hi-Tech Crime (NHTCU) Unit into a new larger agency, The Serious Organised Crime Agency (SOCA), in April 2006 would actually make it harder for businesses to work out to whom they should report an electronic crime. Gibson also attacked the amount of funding the NHTCU has received since its creation in 2001, claiming it has declined annually.

Surprising many audience members, Gibson added that the most effective way to improve online security was by individuals taking small steps such as locking down their desktop. Microsoft has been heavily criticised in the past for the poor levels of security in its products, particularly its Windows operating system.

Gibson aimed the majority of his comments at Alun Michael, minister for Industry and Regulation at the DTI, who was present at the event to launch the CBI report.

Michael responded to Gibson's charge by claiming that he had recently reported a potential attack on his own computer to the help desk at the House of Commons, which passed his report directly to the police.

Another charge made by the Microsoft security chief, who joined Microsoft in July 2005 from the FBI, where he held senior positions as a special agent for 20 years, is that there need to be stronger punishments in place for those who commit electronic crime.

"We can talk and talk about what is in the book [CBI report], but legislation alone will not do it. We can talk about the Computer Misuse Act till the cows come home but unless there are any meaningful punishments for computer crime then none of this makes sense," claimed Gibson.

Earlier this week, the government said it would update the Computer Misuse Act. This will include a maximum 10-year prison sentence for individuals who maliciously impair the operation of a computer, or hinder or prevent access to programs or data.

The CBI report, called Securing Business Value Online, is specifically aimed at small to medium-sized companies which Michael identified as "the weakest link in the chain" when it comes to electronic security. "The old adage that the chain is only as strong as its weakest link, is relevant here," Michael said.

Michael added that effective online security stemmed from taking the right approach to the problem rather simply buying in a fix-all technology. "The problem is at heart how companies are managed and not about waiting for some technological silver bullet."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
66 out of 142 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters