Showing posts with label investment. Show all posts
Showing posts with label investment. Show all posts

Sunday, 14 July 2013

Gartner forecasts a return to IT investment as economy improves

Global IT spending is set to reach $3.7tn by 2014 as the economy improves, according to Gartner's Worldwide IT Spending Forecast.Spending on mobile devices is set to increase
by 6.5% in 2014 to $740bn, compared to $695bn in 2013.Speaking to Computer Weekly, Richard Gordon, research vice-president at Gartner, said: “We are seeing a lower growth in 2013 due to spending being deferred due to folks holding on to smartphones as new operating systems extend the life of handsets.”The data does not take into account whether devices are being bought by IT or by the consumer. Gordon added: “Enterprise IT spending on devices will decline but spending will be picked up by the consumer.”Depending on how companies account for purchases, Gordon did not expect IT budgets to change as a result. He said the IT budget was shifting.

"Businesses are outsourcing and using software as a service (SaaS), rather than investing in their own datacentres," he added.Enterprise software spending is on pace to grow 6.4% in 2013. Gartner's Worldwide IT Spending Forecast showed expanded spending on e-commerce, social and mobile as organisations boost customer relationship systems.According to Gartner, buyers in the customer relationship management (CRM) market are focusing on technologies that enable more targeted customer interactions in multichannel environments – including online channel and marketing campaign management – and technologies enabling customer loyalty management.“Across the board we expect organisations to make strategic investments in CRM. Companies want to invest in big data, social and multichannel marketing to improve CRM,” Gordon explained.The improving economic climate will boost services, according to Gordon.

“As the economy improves there will be an increase in consultancy spend with big programmes around social and mobile as companies make strategic investments in these areas.”Worldwide IT spending forecast (billions of US dollars)Source: Gartner (July 2013)He said Gartner was seeing a decline in the growth of client operating systems, reflecting the decline in the PC industry.The forecast also showed a gradual shift towards SaaS-type licensing over traditional software licensing.

Thursday, 11 July 2013

Paying bug bounties is a better investment than hiring a security team, study claims

Paying rewards to independent security researchers for finding software problems is a vastly better investment than hiring employees to do the same work, according to researchers from the University of California Berkeley.

Their study looked at vulnerability reward programs (VRPs) run by Google and Mozilla for the Chrome and Firefox web browsers.

Over the last three years, Google has paid $580,000 in rewards, and Mozilla has paid $570,000. In the course of those programs, hundreds of vulnerabilities have been fixed in the widely used products.

The programs are very cost effective. Since a North American developer’s salary will cost a company about $100,000 with a 50 percent overhead, “we see that the cost of either of these VRPs is comparable to the cost of just one member of the browser security team,” the researchers wrote.

Additionally, more eyes on the code meant the VRPs uncovered many more software flaws than just one hired developer could find.

The study provides a sound foundation for reward programs, which are not embraced by all vendors. Adobe Systems and Oracle do not pay for vulnerability information.

Microsoft has traditionally not paid bounties, but did implement a one-off program last month. Through July 26, Microsoft will pay up to $11,000 for bugs in its Internet Explorer 11 browser.

Bug bounties have other advantages, such as by reducing the number of vulnerabilities that are sold to malicious actors who would use the information for criminal activity. The programs also make it harder for hackers to find vulnerabilities, the researchers wrote.

But a key difference between Google’s and Mozilla’s programs may affect their effectiveness.

Mozilla pays a flat $3,000 reward for a vulnerability. Google pays on a sliding scale, which ranges from $500 to $10,000. Google judges vulnerabilities and exploits on factors such as difficulty and impact.

Google’s average payout is just $1,000, but the chance of obtaining a much higher reward appears to provide an incentive for more people to participate in its program, the researchers wrote.

Google’s program, while costing about the same as Mozilla’s, “has identified more than three times as many bugs, is more popular and shows similar participation from repeat and first-time participants.”

“This makes sense with an understanding of incentives in lotteries: the larger the potential prize amount, the more willing participants are to accept a lower expected return, which, for VRPs, means the program can expect more participants,” according to the paper.

Also, browser penetration contests such as “Pwnium” run by Google with rewards up to $150,000 sparks more interest among researchers.

“We believe this sort of ‘gamification’ leads to a higher profile for the Chrome VRP, which may help encourage participation, particularly from researchers interested in wider recognition,” the paper said.

“Accordingly, we recommend Mozilla change their reward structure to a tiered system like that of Chrome,” it said.