Newsletter:

Skip Navigation LinksHome > News > Security > Enterprises urged to plug IM security holes

Enterprises urged to plug IM security holes

By Clement James
26 March 2008 07:00AM
Tags: enterprises | urged | plug | im | security | holes

One in four employees has used instant messaging to send information about company plans, finances or password/login credentials, security experts have warned..

FaceTime Communications said that enterprises need to wake up to the use of real-time communications in the workplace and ensure that they have the ability to log, archive and retrieve the communications.

A review of thousands of pages of IM conversations in the recent Société Générale trading scandal revealed that the rogue trader may not have acted alone.

The reports note that much of the trading scheme was discussed over instant messaging, as opposed to more traditional email channels. Société Générale's ability to retrieve these messages provided a clear trail for investigators.

"The financial sector has long led the way in the use of technology, and its adoption of instant messaging is no exception," said Nick Sears, EMEA vice president at FaceTime.

"Employees frequently believe that their IM conversations are private, as the Société Générale case shows.

"By and large the employees are correct as many businesses do not even recognise that real-time communications are being used on their systems, let alone monitor it."

FaceTime added that IM is not the only real-time communication tool that organisations should be wary of when it comes to information leakage and employee collusion.

"Even if you ignore the fact that you cannot scan for malware using traditional security tools, encrypted VoIP is still a major headache for companies in terms of data leakage," said Sears.

"It is not just conversations that go unmonitored. Most VoIP clients allow you to exchange files too, allowing confidential documents to slip easily in and out of the organisation before you can say 'regulatory investigation.'"

Copyright © 2008 vnunet.com

   


Ads by Google



Product Reviews

Star Rating
For this review, I decided to combine these products into a single group of their own. Please keep in mind...
Star Rating
The netVigilance SecureScout EagleBox SP 2.0 is a highly comprehensive vulnerability management product.
Star Rating
The StillSecure VAM appliance is serious vulnerability management in a single device.
Star Rating
Last year for this Group Test, we saw the software version of this product, so this year we were very excited...
Star Rating
Lumension Security's PatchLink Scan is a fairly robust vulnerability scanner.


TopTopics
(7079) -  broadband
(5457) -  telstra
(3218) -  network
(3068) -  internet
(2929) -  wireless
(2476) -  data
(1987) -  iphone
(1887) -  linux
(1632) -  mobile
(1500) -  security
(1345) -  online
(1203) -  digital
(1169) -  phone
(1163) -  yahoo
(1158) -  nbn