Home  |  About  |  Contact

Wednesday, 15 Oct , 2014

Infospectives in SC Magazine – On Implications of JP Morgan’s Doubled CyberSecurity Budget

Share this article

Infospective's owner, Sarah Clarke, joins other industry commentators looking at implications of JP Morgan's 100% hike in planned cyber security spend http://wp.me/p4oO83-LC

The CEO of US investment bank JPMorgan says the company will double its spending in cyber-security following a data breach which affected approximately 84 million account holders…

Asda insurer and 83m JPMorgan customers hacked

…“We had a little problem recently,” said Dimon, referencing the data breach, before adding that the firm intends to double its cyber-security spending from US$ 250 million (£156 million) annually in 2014 to US$ 500 million (£311 million) in five years time…
…Sarah Clarke, former group functions IT risk strategy manager at Aviva and now MD of information security consultancy Infospectives, told SC that the spending is the latest sign of the ‘boom, bust’ budget cycle in the security sector.
Click HERE to read the full article including more from me on the tendency towards incident driven, high profile, but often short-lived commitment to improving security defenses.

Infospectives Security GRC Consultancy

5This article coincides with the launch of our consultancy offerings.  I’ve distilled some hard-won lessons about what works and what doesn’t work in the world of security governance, risk and compliance. It reflects security operations and management experience gained over many years and in many sectors (most recently financial services).
I’m delighted to be focusing on Infospectives full-time now (well almost – there are an incredible amount of exciting things going on with GiveADay at the moment too) and it is great to fulfill an ambition to offer some niche security consultancy. Advice, tips, tricks and analyses designed to guide you around some of the obstacles I have hit quite hard during my time in the trade.
Why not have a look at what we’re up to. If you spot some familiar challenges and would like help to fully understand and meet them, please do get in touch (enquiries@infospectives.co.uk).
Sarah Clarke

Data Protection, Security, and the GDPR: Myths and misconceptions #2

Welcome back! This is a shamefully delayed sequel to my first instalment of security themed GDPR thoughts: Data Protection, Security, and the GDPR: A fraught and fuzzy relationship. Here I look back again over my pre-privacy IT and InfoSec career to spot things likely...

Where and to whom does the GDPR apply?

Yeah, I doubted my sanity going at this one too, but here I am, because working out whether or not the GDPR would apply in different practical and geographical circumstances is proving harder than it really should...for everyone. This regulation has been my almost...

GDPR – You’ve analysed the gaps, but can you close them?

  There is a critical gap for most firms: An inability to interpret and leverage gap analysis, data discovery, and mapping output to actually implement technical data processing change. This article is about the challenges most large firms are facing when trying...

GDPR – The Compliance Conundrum

There is one question related to the General Data Protection Regulation that will arguably cause more ulcers than any other: How much is enough? In some portions of the GDPR 'good' is straightforward. In many others we are asked to respect principles of fairness and...

Opinion: The role of automated data discovery in a GDPR programme

Do you have any online profiles or posts featuring those 4 magic characters: G D P R? If so, whether you are a business decision maker, IT body, security body, charity boss, employed data protection pro, or job seeking data protection pro (less and less likely), you...

When Business Culture Eats Cybersecurity For Breakfast – Part One

A four-part story of budget cuts, blamestorming, breaches and massive bumps in the road to mature security. Wild Speculation & IT Transformation Do you remember Nick Leeson? On February 23rd 1995 he sent a fax telling bosses at Barings Bank he was ill and wanted...

Cyber Insurers Dictating Cybersecurity Standards?

A run down of the key challenges with choosing and using cyber insurance called out in the last few months. It looks entirely possible you will have 'adequate' security dictated by your insurers, so it is your job to understand the risk based yardstick they're using...

There Is No Such Thing As Information Security Risk

Having worked in IT and Information Security for 13 years, I've come to the conclusion that there is no such thing as information security risk. There are just business risks that have one or more security or IT related causes. There is a fundamental and persistent...

We welcome the Children’s Commissioner report “Who knows what about me?” which shows how children’s data is routinely collected online. The report points out that children are among the first to be ‘datafied’ from birth, including policy and practice in schools, and comments on the datafication of children in the education sector; school databases, classroom…read the full article on the Defend Digital Me blog

Read more

Children’s Comissioner on concerning use of school children’s data

We welcome the Children’s Commissioner report "Who knows what about me?" which shows how children’s data is routinely collected online. The report points out that children are among the first to be ‘datafied’ from birth, including policy and practice in schools, and...

The IT Asset Disposal Vicious Cycle

Most retired equipment is ground up for minimal financial and recycling return... ...that model is financially, environmentally, and socially unsustainable. The way we all do business is changing. Increasing numbers of staff work flexibly and use their own kit....