Skip to main content

Proceeding contribution from Barry Gardiner (Labour) in the House of Commons on Wednesday, 23 November 2005. It occurred during Adjournment debate on Cyber Security.


Cyber Security

: I have noted the hon. Gentleman's comments and his strong recommendation that we should do that. Obviously, he would not expect me to make any announcements at this stage, but the Government should consider those sensible suggestions and arrive at an appropriate conclusion. My Department has had a long-standing role in identifying and promoting best practice in information security, with a particular focus on the needs of smaller businesses. The hon. Gentleman will be aware, I am sure, of the Department's biennial information security breaches survey, one of the best of its kind in the world, which looks at the changing pattern of security problems as they are experienced by UK companies. The last survey reported some positive developments in relation to how the subject was being treated by companies—some 75 per cent. of managers thought that information security was a high priority—but it still found a worrying lack of awareness and preparedness. Only 20 per cent. of respondents had a business continuity or disaster recovery plan. I suspect that the next survey, on which the fieldwork is under way as we speak, will give us a good insight into how business is responding to the current surge in malicious software. The survey assists us in many ways—and I should say in passing that sponsorship and input from business make it a great example of public-private partnership. It has allowed us to focus our outreach efforts to small business against a clear understanding of their problems. Let me illustrate that. UK industry classifies 51 per cent. of its information as highly sensitive, but small business spends less than 1 per cent. of its IT budget on protecting that asset. It is clear that investing in IT security is perceived as a burden by that group, especially as identifying a return on the money invested is so hard to calculate. Yet it can cost upwards of £10,000 to rectify a security breach. We aim to get the message across that a small investment in appropriate systems and products will increase security exponentially. The material that my Department has produced for smaller businesses is rightly regarded as among the most effective in the EU. My Department looks to work with high profile partners to support the dissemination of these ideas. We are fortunate in having recently completed one successful project with the Institute of Directors and there is another one with the CBI and Ernst and Young, which is due for launch in the new year. That project will seek to use the supply chain as a method for reaching smaller businesses and will involve a series of regional roadshows. The survey also allows us to measure how businesses are treating information security as a business issue. It has always been the Department's objective to put information risk at the heart of the UK business approach to risk management. To that end, the Department has collaborated with businesses in the production of information security management standards, and we have worked together to produce two key standards: a guideline document and a specification for an information security management system. I am glad to say that both those UK initiatives have been recognised by the international standards community and have been adopted as international standards. The publication of the information management systems specification took place as recently as 15 October, and there is every prospect that it will become a major tool for businesses that wish to deal with information risk systematically. I am mindful that we need to promote good practice to support e-business—of which I understand the hon. Gentleman has personal experience—and I assure him that the Government remain committed to promoting a vibrant e-business community with confidence in its ability to work securely. As I have explained, it is not the Government's role to manage the internet, or regulate how business is conducted through it. We need to regulate to allow e-business to flourish and, through laws such as the Computer Misuse Act 1990, provide a deterrent to those who would seek to conduct crime online.


Secondary information

Type
Proceeding contribution
Reference
439 c480-1WH 
Session
2005-06
Chamber / Committee
Westminster Hall
Subjects
Hacking Cybersecurity
Link
View this Proceeding contribution on www.publications.parliament.uk