Most IT Security Pros Disabling Security Functions In Favor Of Network Speed

  /     /     /  
Publicated : 22/11/2024   Category : security


Most IT Security Pros Disabling Security Functions In Favor Of Network Speed


New survey shows dilemma faced by organizations over performance trade-offs with network security products



More than 80 percent of organizations disable functions in their network security products because they slow the network, according to a newly released survey.
Crossbeam Systems surveyed 500 network security, IT, and C-level executives at companies worldwide and found that 90 percent say theres a trade-off between security and throughput. Around 67 percent say security is a higher priority than throughput performance when evaluating a security product.
Its the age-old problem of balancing security and productivity. We found in the survey that they are having to make significant trade-offs between security and performance ... They are having to switch off functionality they paid for to meet their performance goals, says Peter Doggart, director of product marketing at Crossbeam.
Organizations are keeping their firewall, IDS, network access control, and IPSec functions turned on, but they are shutting off application control, user identification control, and some anti-malware features. In next-generation firewall products, for instance, 91 percent are using stateful firewall features; 73 percent, NAT; 71 percent, IPsec; and 65 percent, IDS/IPS.
Only 29 percent had deployed the anti-malware functions in these next-generation firewalls; 29 percent, user ID control; 33 percent, application control; 34 percent, antivirus; and 45 percent, Web filtering.
Every platform has this problem. You turn on more security processing and performance goes down, Doggart says. We need to makes sure customers are turning on this functionality to protect themselves.
But the reality of their service-level agreement requirements and misleading performance claims by network security vendors is making this impossible, according to Doggart.
More than 93 percent of the survey respondents dont trust the performance metrics that security hardware vendors provide on their data sheets, and 58 percent say they dont trust the performance metrics themselves. More than 60 percent say they had to purchase additional hardware to make up for unmet claims by security hardware vendors.
But its not just the security vendors: The customers have to better vet the tools, according to the study. Almost half of those surveyed did not conduct any real-world testing of the products before rolling them out. I think youre asking for trouble if youre not doing that. And [in the survey], of those that did do real-world testing, half never turned on IPS, Doggart notes. Both sides are culpable.
A copy of the survey report is available for download
here
.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Most IT Security Pros Disabling Security Functions In Favor Of Network Speed